Book Image

Mastering Splunk

By : James D. Miller
Book Image

Mastering Splunk

By: James D. Miller

Overview of this book

Table of Contents (18 chapters)
Mastering Splunk
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Strategic knowledge management


Splunk knowledge management helps you to transition from tactical individual use to the strategic empowerment of the enterprise. Typically, knowledge management focuses on runtime (or search-time) event manipulation rather than the preindexed setup and processes, which are more Splunk administrative in nature.

Note that it is a good idea for someone involved in knowledge management to have an experience of working with Splunk's administrative matters or at least a fundamental understanding of the basic matters, listed as follows, and a strong understanding of the data and use cases.

Let's see what the prerequisites for knowledge management are:

  • Apps: If your enterprise uses more than one Splunk app and it will (for example, network administration and website log review might be two completely different user groups with completely different goals), you need to understand how Splunk apps are organized and how app object management works within multi-app deployments...