Book Image

Implementing Splunk (Update)

Book Image

Implementing Splunk (Update)

Overview of this book

Table of Contents (20 chapters)
Implementing Splunk Second Edition
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

A quick example


Once you have selected a data model (in our case Aviation Games), from the Select an object page, we can choose Processing Errors, which will land us on the New Pivot (Pivot Editor):

To build a simple pivot, we can take the following quick steps:

  1. Add/verify the filters.

    Remember, All time is the default; this will include all results found over all time. You can click on the pencil and amend this filter to be based upon any of Splunk's Presets or a specific Date Range:

    For this example, we'll just leave the default selection.

  2. Configure the Split Rows

    Directly under Filters is Split Rows. For Split Rows, I've selected date_month:

  3. After making the selection, you are able to provide additional settings for the selected row:

    I've provided a new name (Label) for the row (my_Month) and left the defaults for Sort, Max Rows (to display), and Totals.

  4. Configure the Split Columns

    Moving to the upper-right side of the Pivot page, we have Split Columns. For Split Columns, I've selected date_mday...