Book Image

Splunk Essentials - Second Edition

By : Betsy Page Sigman, Erickson Delgado
Book Image

Splunk Essentials - Second Edition

By: Betsy Page Sigman, Erickson Delgado

Overview of this book

Splunk is a search, analysis, and reporting platform for machine data, which has a high adoption on the market. More and more organizations want to adopt Splunk to use their data to make informed decisions. This book is for anyone who wants to manage data with Splunk. You’ll start with very basics of Splunk— installing Splunk—and then move on to searching machine data with Splunk. You will gather data from different sources, isolate them by indexes, classify them into source types, and tag them with the essential fields. After this, you will learn to create various reports, XML forms, and alerts. You will then continue using the Pivot Model to transform the data models into visualization. You will also explore visualization with D3 in Splunk. Finally you’ll be provided with some real-world best practices in using Splunk.
Table of Contents (15 chapters)
Splunk Essentials Second Edition
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Preface

Data inputs


As you may have noticed, any configuration you make in the Splunk portal corresponds to a *.conf file written to the disk. The same goes for the creation of data inputs; it creates a file called inputs.conf. Now that you have an index to store your machine's Windows Event Logs, let us go ahead and create a data input for it, with the following steps:

  1. Go to the Splunk home page.

  2. Click on your Destinations app. Make sure you are in the Destinations app before you execute the next steps.

  3. In the Splunk navigation bar, select Settings.

  4. Under the Data section, click on Data inputs.

  5. On the Data inputs page, click on the Local event log collection type as shown in the following screenshot:

  6. In the next page select the Application and System log types.

  7. Change the index to wineventlog. Compare your selections with the following screenshot:

  8. Click Save.

  9. On the next screen, confirm that you have successfully created the data input, as shown in the following screenshot:

Before we proceed further,...