-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
Mastering Splunk
By :
Machines constantly generate data, usually in a raw form that is most efficient for processing by machines, but not easily understood by "human" data consumers. Splunk has the ability to identify unique identifiers and/or result or status codes within the data. This gives you the ability to enhance the readability of the data by adding descriptions or names as new search result fields. These fields contain information from an external source such as a static table (a CSV file) or the dynamic result of a Python command or a Python-based script.
Splunk's lookups can use information within returned events or time information to determine how to add other fields from your previously defined external data sources.
To illustrate, here is an example of a Splunk static lookup that:
Business Unit value in an eventBusiness Unit Name field...
Change the font size
Change margin width
Change background colour