Book Image

Splunk Essentials - Second Edition

By : Betsy Page Sigman, Erickson Delgado
Book Image

Splunk Essentials - Second Edition

By: Betsy Page Sigman, Erickson Delgado

Overview of this book

Splunk is a search, analysis, and reporting platform for machine data, which has a high adoption on the market. More and more organizations want to adopt Splunk to use their data to make informed decisions. This book is for anyone who wants to manage data with Splunk. You’ll start with very basics of Splunk— installing Splunk—and then move on to searching machine data with Splunk. You will gather data from different sources, isolate them by indexes, classify them into source types, and tag them with the essential fields. After this, you will learn to create various reports, XML forms, and alerts. You will then continue using the Pivot Model to transform the data models into visualization. You will also explore visualization with D3 in Splunk. Finally you’ll be provided with some real-world best practices in using Splunk.
Table of Contents (15 chapters)
Splunk Essentials Second Edition
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Preface

Creating a radio input


Now we are going to create radio inputs with dynamic search options. This will allow viewers to select server and status types, and will affect the information rendered by the panels:

  1. Click on Edit | Edit Panels.

  2. Select Add Input | Radio.

  3. Click on the Editicon in the newly created input.

  4. In the Labelfield, type in Select Server.

  5. Enable Search on Changeby checking the checkbox.

  6. In the Token field, type server:

  7. Scroll down to Static Optionsand click on it. In Static Options, add Name as ALLand Value as *.

  8. Click Dynamic Options, then fill inSearch String, entering the following search command:

          SPL> index=main | top server_ip
    
  9. Change the time range from All time to Last 60 minutes.

  10. In Field For Label, type in server_ip.

  11. In Field For Value, type in server_ip.

  12. Now scroll back up to Token Options.

  13. For Default, select ALL.

  14. For Initial Value, select ALL.

  15. Click Applyand you're done:

Now that you have configured the radio input with dynamic search options, you will see that the selection...