Book Image

Data Analytics Using Splunk 9.x

By : Dr. Nadine Shillingford
5 (1)
Book Image

Data Analytics Using Splunk 9.x

5 (1)
By: Dr. Nadine Shillingford

Overview of this book

Splunk 9 improves on the existing Splunk tool to include important features such as federated search, observability, performance improvements, and dashboarding. This book helps you to make the best use of the impressive and new features to prepare a Splunk installation that can be employed in the data analysis process. Starting with an introduction to the different Splunk components, such as indexers, search heads, and forwarders, this Splunk book takes you through the step-by-step installation and configuration instructions for basic Splunk components using Amazon Web Services (AWS) instances. You’ll import the BOTS v1 dataset into a search head and begin exploring data using the Splunk Search Processing Language (SPL), covering various types of Splunk commands, lookups, and macros. After that, you’ll create tables, charts, and dashboards using Splunk’s new Dashboard Studio, and then advance to work with clustering, container management, data models, federated search, bucket merging, and more. By the end of the book, you’ll not only have learned everything about the latest features of Splunk 9 but also have a solid understanding of the performance tuning techniques in the latest version.
Table of Contents (18 chapters)
1
Part 1: Getting Started with Splunk
5
Part 2: Visualizing Data with Splunk
10
Part 3: Advanced Topics in Splunk

Exploring inputs.conf using the Splunk Add-on for Microsoft Windows

To appreciate the power of Splunk, we have to first ingest data. This data can come from various sources using various methods. However, we will need to tell Splunk how to ingest this data. This process of creating new configurations that instruct Splunk on where to find the new data is called onboarding. It can be accomplished by modifying configuration files, running commands using the Splunk CLI, or by using readymade forms or widgets in Splunk Web. In this section, we will investigate how Splunk inputs can be configured by modifying the Splunk inputs.conf configuration file. Every app in Splunk has a basic structure (bin, etc, and default folders). Remember that the default configuration files can be found in the default directory. However, we should never make changes within this directory. Instead, any new configurations or modifications should be made in the local directory. Therefore, the default inputs.conf...