Book Image

Splunk Operational Intelligence Cookbook

Book Image

Splunk Operational Intelligence Cookbook

Overview of this book

Table of Contents (17 chapters)
Splunk Operational Intelligence Cookbook
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

Index

A

  • abnormally-sized web requests
    • finding / Finding abnormally sized web requests, How to do it..., There's more...
    • anomalies command / The anomalies command
    • anomalousvalues command / The anomalousvalues command
    • cluster command / The cluster command
  • abnormal user behavior
    • alerting on / Alerting on abnormal user behavior, How to do it..., How it works...
  • abnormal user purchases
    • without checkouts, alerting on / Alerting on abnormal user purchases without checkouts
  • abnormal web page response times
    • alerting on / Alerting on abnormal web page response times, How to do it...
  • accelerated report
    • status, viewing / Viewing the status of an accelerated report
  • acceleration, data model
    • advanced configuration / Advanced configuration of data model acceleration
  • acceleration summary information, data model
    • viewing / Viewing data model and acceleration summary information
  • activity reports
    • drilling down on / Dynamically drilling down on activity reports, How to do it..., How it works..., There's more…
  • alert actions
    • about / Introduction
    • e-mail notification / Introduction
    • script execution / Introduction
    • RSS notification / Introduction
    • summary indexing / Introduction
    • alert manager, alert in / Introduction
  • alerting
    • manual, URL / Introduction
    • on abnormal web page response times / Alerting on abnormal web page response times, How to do it..., How it works..., There's more...
    • on errors, during checkout in real time / Alerting on errors during checkout in real time, How to do it..., How it works...
    • on abnormal user behavior / Alerting on abnormal user behavior, How to do it..., How it works...
    • on abnormal user purchases, without checkouts / Alerting on abnormal user purchases without checkouts
    • scripted response, on failure / Alerting on failure and triggering a scripted response, How to do it..., How it works..., There's more…
    • scripted response, on triggering / Alerting on failure and triggering a scripted response, How to do it..., How it works..., There's more…
    • on predicted sales exceed inventory / Alerting when predicted sales exceed inventory, How to do it..., How it works...
  • alerts
    • about / Introduction
    • scheduled alert / Introduction
    • per-result alert / Introduction
    • rolling-window alert / Introduction
    • triggered alert, viewing in alert manager / Viewing triggered alerts in Splunk's Alert manager
    • building, via configuration file / Building alerts via a configuration file
    • RSS feed notification action, adding / Adding an RSS feed notification action to an alert
  • anomalies command / The anomalies command
  • anomalousvalues command
    • about / The anomalousvalues command
    • URL / The anomalousvalues command
  • append, outputlookup command / How it works...
  • append command
    • URL / There's more…
  • application
    • creating, from another application / Creating an application from another application
  • application errors
    • ticket, creating for / Creating a ticket for application errors, How to do it..., How it works...
  • application logs
    • data model, creating for / Creating a data model for application logs, How to do it..., How it works...
  • application navigation
    • customizing / Customizing the application's navigation, How to do it..., How it works..., There's more…
  • applications
    • functional performance, charting / Charting the application's functional performance, How to do it..., There's more...
    • memory usage, charting / Charting the application's memory usage, How to do it..., See also
  • applications functional statistics
    • area chart, creating / Creating an area chart of the application's functional statistics, How to do it..., How it works...
  • area
    • distributions, mapping by / Mapping different distributions by area
  • area chart
    • about / Introduction
    • of applications functional statistics, creating / Creating an area chart of the application's functional statistics, How to do it..., How it works...
  • ARIN
    • searching, for given IP address / Searching ARIN for a given IP address, How to do it..., There's more...
  • associate command
    • about / There's more…
  • Auto-Extracted, object attribute / Introduction
  • automatic product code lookup
    • creating / How to do it..., How it works...
  • average amount spent by category
    • displaying, bar chart used / Using a bar chart to show the average amount spent by category, How to do it..., How it works...
  • average execution time
    • calculating, for multi-tier web requests / Calculating the average execution time for multi-tier web requests, How to do it..., There's more…
    • calculating, without using join / Calculating the average execution time without using a join
  • average response time
    • of function calls, predicting / Predicting the average response time of function calls
  • average session time
    • on website, calculating / Calculating the average session time on a website, How to do it..., There's more...

B

  • backfilling
    • number of purchases, by city / Backfilling the number of purchases by city, How to do it..., How it works...
    • summary index / How it works...
    • summary index, from within search directly / Backfilling a summary index from within a search directly
  • bar chart
    • about / Introduction
    • using, to display average amount spent by category / Using a bar chart to show the average amount spent by category, How to do it..., How it works...
  • blogs
    • URL / Getting ready
  • Boolean operators
    • AND / Introduction
    • OR / Introduction
    • NOT / Introduction

C

  • calendar heatmap
    • of product purchases, adding / Adding a calendar heatmap of product purchases, How to do it...
  • cart additions
    • percentage from product views, searching / Searching for the percentage of cart additions from product views
  • category
    • average amount spent displaying, bar chart used / Using a bar chart to show the average amount spent by category, How to do it...
  • chart command / Introduction
  • chart drilldown options
    • Google search, triggering from / Triggering a Google search from the chart drilldown options
  • charts
    • drilldown feature, disabling / Disabling the drilldown feature in tables and charts
  • checkout, transaction
    • ends with / Starts with a website visit, ends with a checkout
  • checkout errors
    • real-time alert, creating on / Alerting on errors during checkout in real time, How to do it..., How it works...
  • child object constraint / Introduction
  • child objects / Introduction
  • city
    • number of purchases, backfilling / Backfilling the number of purchases by city, How to do it..., How it works...
  • CLI
    • file data input, adding via / Adding a file or directory data input via the CLI
    • directory data input, adding via / Adding a file or directory data input via the CLI
    • URL / Adding a file or directory data input via the CLI
    • network input, adding via / Adding a network input via the CLI
  • cluster command
    • about / The cluster command
    • URL / The cluster command
  • column chart
    • about / Introduction
  • commands
    • generating / How it works...
    • reporting / How it works...
    • streaming / How it works...
  • Common Information Model (CIM) / Introduction, There's more…
  • completed transactions
    • versus hourly count of sessions, calculating / Calculating an hourly count of sessions versus completed transactions, How to do it..., How it works..., There's more...
  • concurrency command
    • URL / How it works...
  • configuration file
    • alerts, building via / Building alerts via a configuration file
  • configuration files
    • URL / How it works..., How it works...
  • createinapp, outputlookup command / How it works...
  • create_empty, outputlookup command / How it works...
  • curl
    • URL / Getting ready
  • custom search command
    • creating, to format product names / Creating a custom search command to format product names, How to do it..., How it works...
  • custom search commands
    • generating / How it works...
    • reporting / How it works...
    • streaming / How it works...

D

  • D3.js
    • URL / How it works..., How it works...
  • dashboards
    • for Operational Intelligence / Introduction
    • adding / Adding dashboards and reports, How to do it..., How it works...
    • organizing / Organizing the dashboards more efficiently, How to do it..., How it works...
    • PDF delivery, scheduling / Scheduling the PDF delivery of a dashboard, How to do it..., How it works...
    • URL / How it works...
  • data
    • getting, through network ports / Getting data through network ports, How to do it..., How it works...
    • gathering, Universal Forwarder used / Using the Universal Forwarder to gather data, How to do it..., There's more...
    • enriching, with visualizations / Introduction
  • database connections
    • total number of database connections, counting / Counting the total number of database connections, How to do it..., How it works...
  • data files
    • one-time indexing, via Spunk CLI / One-time indexing of data files via the Splunk CLI
  • data model
    • creating, for web access logs / Creating a data model for web access logs, How to do it..., How it works..., There's more...
    • searching, search interface used / Searching data models using the search interface
    • accelerating / Accelerating data models, How to do it..., There's more...
    • acceleration, URL / How it works...
    • viewing / Viewing data model and acceleration summary information
    • acceleration summary information, viewing / Viewing data model and acceleration summary information
    • acceleration, advanced configuration / Advanced configuration of data model acceleration
  • data model acceleration / Introduction
  • datamodel command
    • URL / Searching data models using the search interface
  • data sources
    • URL / Introduction
    • converging / Introduction
  • data summarization
    • about / Introduction
    • methods / Introduction
  • data summarization, methods
    • about / Introduction
    • summary indexing / Introduction
    • report acceleration / Introduction
    • data model acceleration / Introduction
  • DB actions
    • relationships, analyzing to memory utilization / Analyzing relationships of DB actions to memory utilization
  • DB Connect
    • about / Lookups
    • URL / Looking up inventory from an external database
    • using, for direct external DB lookups / Use DB Connect for direct external DB lookups
  • DB lookups, direct external
    • DB Connect, used for / Use DB Connect for direct external DB lookups
  • dedup command / Introduction
  • Developing Views and Apps for Splunk Web manual
    • URL / There's more...
  • directories
    • indexing / Indexing files and directories, How to do it...
  • directory data input
    • adding, via CLI / Adding a file or directory data input via the CLI
    • adding, via inputs.conf / Adding a file or directory input via inputs.conf
  • distributions
    • mapping, by area / Mapping different distributions by area
  • DNS lookups
    • enabling / Enabling automatic external field lookups
  • documentation, Splunk
    • URL / Limiting workflow actions by event types
  • drilldown feature
    • disabling, in charts / Disabling the drilldown feature in tables and charts
    • disabling, in tables / Disabling the drilldown feature in tables and charts
    • options, URL / Disabling the drilldown feature in tables and charts
  • drilling down
    • dynamically, on activity reports / Dynamically drilling down on activity reports, How to do it..., How it works..., There's more…
  • driver
    • installing, URL / How to do it…

E

  • error
    • about / Introduction
  • Eval-Expression, object attribute / Introduction
  • eval command / Introduction
  • event object constraint / Introduction
  • event objects / Introduction
  • events
    • defining / Defining maximum pause, span, and events in a transaction
  • event types
    • about / Defining event types and tags, How it works...
    • URL / Defining event types and tags
    • defining / How to do it...
    • adding, via eventtypes.conf / Adding event types and tags via eventtypes.conf and tags.conf
    • workflow actions, limiting by / Limiting workflow actions by event types
  • eventtypes.conf
    • event types, adding via / Adding event types and tags via eventtypes.conf and tags.conf
  • existing saved search
    • modifying, to populate lookup table / Modifying an existing saved search to populate a lookup table
  • external database
    • inventory, looking up from / Looking up inventory from an external database, How to do it…, There's more...
  • external field lookups
    • automatic external field lookups, enabling / Enabling automatic external field lookups

F

  • <filename>, outputlookup command / How it works...
  • field
    • every field, tabulating / Tabulating every field
    • removing / Removing fields, then tabulating everything else
  • field extractions
    • defining / Defining field extractions, How to do it..., How it works...
  • fields
    • working with / Introduction
    • relationships between, identifying / Introduction
  • fields command / Introduction
  • file data input
    • adding, via CLI / Adding a file or directory data input via the CLI
    • adding, via inputs.conf / Adding a file or directory input via inputs.conf
  • files
    • indexing / Indexing files and directories, How to do it...
  • filter gauge
    • about / Introduction
  • force-directed graph
    • of web hits, adding / Adding a force-directed graph of web hits, How to do it..., How it works...
  • form
    • creating, to search web activity / Creating a form to search web activities, How to do it..., How it works...
    • Submit button, adding / Adding a Submit button to your form
    • web page activity reports, linking to / Linking web page activity reports to the form, How to do it..., There's more...
  • form inputs
    • Dropdown / Introduction
    • radio / Introduction
    • text / Introduction
    • time / Introduction
  • function calls
    • average response time, predicting / Predicting the average response time of function calls
  • future values
    • predicting / Introduction

G

  • gauge
    • using, to display number of errors / Using a gauge to display the number of errors, How to do it..., How it works...
  • geographical map
    • of visitors, displaying / Displaying a geographical map of visitors, How to do it..., How it works...
  • geographic location
    • purchases, pivoting by / Pivoting purchases by geographical location, How to do it..., How it works...
  • Geo IP, object attribute / Introduction
  • geostats command / Mapping different distributions by area
  • Google search
    • triggering, for given reason / Triggering a Google search for a given error, How to do it..., How it works...
    • triggering, from chart drilldown options / Triggering a Google search from the chart drilldown options
  • graphical user interface (GUI) / Introduction

H

  • head command / Introduction
  • heat map
    • about / Introduction
  • High Performance Analytics Store (HPAS) / Introduction
  • host
    • number of method requests, charting / Charting the number of method requests by type and host, How to do it..., How it works...
  • hostnames
    • adding, to IP addresses / Adding hostnames to IP addresses, How it works..., There's more…
  • hourly count of sessions
    • versus completed transactions, calculating / Calculating an hourly count of sessions versus completed transactions, How to do it..., How it works..., There's more...
    • summary index, generating search / How it works...
    • summary index, reporting off / How it works...
    • summary index, generating frequently / Generating the summary more frequently
    • summary index overlaps, avoiding / Avoiding summary index overlaps and gaps
    • summary index gaps, avoiding / Avoiding summary index overlaps and gaps

I

  • inputs.conf
    • file data input, adding via / Adding a file or directory input via inputs.conf
    • directory data input, adding via / Adding a file or directory input via inputs.conf
    • network input, adding via / Adding a network input via inputs.conf
  • inventory
    • looking up, from external database / Looking up inventory from an external database, How to do it…, There's more...
  • IP addresses
    • suspect IP addresses, flagging / Flagging suspicious IP addresses, How to do it..., How it works...
    • malicious IP addresses, lookup table creating for / How to do it..., How it works...
    • hostnames, adding / Adding hostnames to IP addresses, How it works..., There's more…
    • ARIN, searching for / Searching ARIN for a given IP address, How to do it..., How it works...
  • item views
    • line chart, creating / Creating a line chart of item views and purchases over time, How to do it…

J

  • Java Bridge Server / How it works...
  • Java Virtual Machine (JVM) / How it works...
  • join
    • URL / There's more…

K

  • Knowledge Manager documentation
    • URL / Introduction

L

  • labels
    • adding, to single value pack / Adding labels to a single value panel
  • line chart
    • about / Introduction
    • of item views, creating / Creating a line chart of item views and purchases over time, How to do it…
    • of purchases over time, creating / Creating a line chart of item views and purchases over time, How to do it…
  • logic
    • creating, for urgency / Creating logic for urgency
  • Lookup, object attribute / Introduction
  • lookup command / Introduction
  • lookups
    • about / Lookups
    • manually, adding to Splunk / Manually adding the lookup to Splunk
  • lookup table
    • of malicious IP addresses, creating / How to do it..., How it works...
    • populating, existing saved search used / Modifying an existing saved search to populate a lookup table

M

  • map
    • about / Introduction
  • map panel
    • adding, SimpleXML used / Adding a map panel using SimpleXML
  • marker gauge
    • about / Introduction
  • max, outputlookup command / How it works...
  • maximum concurrent checkouts
    • displaying / Displaying the maximum concurrent checkouts, How to do it..., How it works...
  • maximum number of concurrent sessions over time
    • displaying / Displaying the maximum number of concurrent sessions over time, How to do it..., How it works...
  • maximum pause
    • defining / Defining maximum pause, span, and events in a transaction
  • method requests
    • timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., How it works...
    • by host / Method requests, views, and response times by host
  • modular inputs
    • using / Using modular inputs, How to do it..., There's more...
  • monitor input type
    • about / How it works...
  • multi-tier web requests
    • average execution time, calculating / Calculating the average execution time for multi-tier web requests, How to do it..., There's more…

N

  • NAT (Network Address Translation) / How it works...
  • network input
    • adding, via CLI / Adding a network input via the CLI
    • adding, via inputs.conf / Adding a network input via inputs.conf
  • network ports
    • data, getting through / Getting data through network ports, How to do it..., How it works..., There's more...
  • number of errors
    • displaying, gauge used / Using a gauge to display the number of errors, How to do it..., There's more…
  • number of method requests
    • charting, by type / Charting the number of method requests by type and host, How to do it..., How it works...
    • charting, by host / Charting the number of method requests by type and host, How to do it..., How it works...
  • number of purchases
    • by city. backfilling / Backfilling the number of purchases by city, How to do it..., How it works..., There's more...
    • summary index, generating search / How it works...
    • summary index, backfilling / How it works...

O

  • object attributes
    • Auto-Extracted / Introduction
    • Eval-Expression / Introduction
    • Lookup / Introduction
    • Regular Expression / Introduction
    • Geo IP / Introduction
  • object constraint
    • event object constraint / Introduction
    • search object constraint / Introduction
    • transaction object constraint / Introduction
    • child object constraint / Introduction
  • object types
    • event objects / Introduction
    • search objects / Introduction
    • transaction objects / Introduction
    • child objects / Introduction
  • one-time indexing
    • of data files, via Spunk CLI / One-time indexing of data files via the Splunk CLI
  • OpenStreetMap service
    • URL / How it works...
  • Operational Intelligence application
    • creating / Creating an Operational Intelligence application, How to do it..., How it works...
    • creating, from another application / Creating an application from another application
  • Operational Intelligence dashboard
    • creating / Creating an Operational Intelligence dashboard, How to do it..., There's more...
    • permissions, changing / Changing dashboard permissions
  • outputlookup command
    • <filename> / How it works...
    • <tablename> / How it works...
    • append / How it works...
    • max / How it works...
    • create_empty / How it works...
    • createinapp / How it works...
  • outputs.conf
    • receiving indexer, adding via / Add the receiving indexer via outputs.conf
  • overlay
    • adding, to Sessions Over Time chart / Adding an overlay to the Sessions Over Time chart

P

  • PDF delivery
    • of dashboard, scheduling / Scheduling the PDF delivery of a dashboard, How to do it..., How it works...
  • per-result alert / Introduction
  • permission
    • of saved reports, changing / Changing the permissions of saved reports
    • URL / How to do it...
  • pie chart
    • about / Introduction
    • using, to show most accessed web pages / Using a pie chart to show the most accessed web pages, How to do it..., How it works...
  • pivot charting
    • top error codes / Pivot charting top error codes, How it works...
  • pivot command
    • used, for pivot searching / Pivot searching using the pivot command and search interface
    • URL / Pivot searching using the pivot command and search interface
  • pivoting
    • total sales transactions / Pivoting total sales transactions, How to do it..., How it works...
    • slowest responding web pages / Pivoting slowest responding web pages, How to do it..., How it works…
  • potential session spoofing
    • identifying / Identifying potential session spoofing, How to do it..., How it works...
    • logic, creating for urgency / Creating logic for urgency
  • predict command
    • URL / Predicting the average response time of function calls
  • product code descriptions
    • looking up / Looking up product code descriptions, How to do it..., There's more...
  • product names
    • formatting, custom search command created / Creating a custom search command to format product names, How to do it..., How it works...
  • product purchases
    • calendar heatmap, adding / Adding a calendar heatmap of product purchases, How to do it...
  • purchases
    • pivoting, by geographic location / Pivoting purchases by geographical location, How to do it..., How it works...
  • purchases over time
    • line chart, creating / Creating a line chart of item views and purchases over time, How to do it…
  • Python application
    • creating, to return unique IP addresses / Creating a Python application to return unique IP addresses, How to do it..., There's more...

R

  • radial gauge
    • about / Introduction
  • ranges
    • value based on, coloring / Coloring the value based on ranges
  • rare command / Introduction
  • raw event data
    • making, readable / Making raw event data readable, How to do it..., How it works..., There's more...
  • real-time alert
    • creating / Alerting on errors during checkout in real time, How to do it..., How it works...
    • URL / There's more...
  • real-time searches
    • identifying / Identify the real-time searches that are running
  • receiving indexer
    • adding, via outputs.conf / Add the receiving indexer via outputs.conf
  • regular expression (regex) attribute / How to do it...
  • Regular Expression, object attribute / Introduction
  • relationships
    • between fields, identifying / Introduction
  • rename command / Introduction
  • replace command / Introduction
  • report acceleration
    • about / Introduction
    • ease / Introduction
  • reports
    • about / Introduction, Introduction
    • adding / Adding dashboards and reports, How to do it..., How it works...
    • scheduling, URL / How it works...
  • response codes
    • web page response codes, charting / Charting web page response codes, How it works..., There's more...
    • error web page response codes, totaling / Totaling success and error web page response codes
    • success web page response codes, totaling / Totaling success and error web page response codes
  • response times
    • timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more..., Method requests, views, and response times by host
    • by host / Method requests, views, and response times by host
    • scatter chart, using to identify discrete requests / Using a scatter chart to identify discrete requests by size and response time, How to do it..., How it works..., There's more...
  • response time statistics, web page
    • displaying / Displaying web page response time statistics, How to do it..., There's more...
  • REST API
    • about / Introduction
    • for unique page views, querying remotely / Remotely querying Splunk's REST API for unique page views, How to do it..., How it works...
  • REST Wikipedia page
    • URL / How it works...
  • rolling-window alert / Introduction
  • RSS feed notification action
    • adding, to alert / Adding an RSS feed notification action to an alert

S

  • sales
    • predicted sales exceed inventory, alerting on / Alerting when predicted sales exceed inventory, How to do it..., How it works...
  • sample data
    • loading / Loading the sample data for this book, How to do it..., How it works...
  • saved reports
    • permissions, changing / Changing the permissions of saved reports
  • saved searches
    • about / Introduction
  • scatter chart
    • about / Introduction
    • using, to identify discrete requests by size / Using a scatter chart to identify discrete requests by size and response time, How to do it..., There's more...
    • using, to identify discrete requests by response time / Using a scatter chart to identify discrete requests by size and response time, How to do it..., There's more...
    • time series data points, using with / Using time series data points with a scatter chart
    • time series data points, using / Using time series data points with a scatter chart
  • scheduled alert / Introduction
  • scripted inputs
    • using / Using scripted inputs, How to do it..., How it works...
  • scripted response
    • failure, alerting on / Alerting on failure and triggering a scripted response, How to do it..., There's more…
    • triggering, alerting on / Alerting on failure and triggering a scripted response, How to do it..., There's more…
  • search
    • results, paginating / Paginating the results of your search
  • search command / Introduction
  • searches
    • about / Introduction
    • saving / Introduction
  • searching
    • pivoting, pivot command used / Pivot searching using the pivot command and search interface
    • pivoting, search interface used / Pivot searching using the pivot command and search interface
  • search interface
    • used, for searching data model / Searching data models using the search interface
    • creating, for application logs / Creating a data model for application logs, How to do it..., How it works...
    • used, for pivot searching / Pivot searching using the pivot command and search interface
  • search manager
    • time range, changing / Changing the time range on the search manager
  • search object constraint / Introduction
  • search objects / Introduction
  • Search Processing Language (SPL) / Introduction, Introduction
    • about / Introduction
  • Sessions Over Time chart
    • overlay, adding / Adding an overlay to the Sessions Over Time chart
  • session state table
    • creating / Creating a session state table, How to do it..., How it works...
  • session token
    • authenticating with / Authenticating with a session token
  • SimpleXML
    • about / Introduction
    • modifying / Modifying the SimpleXML directly
    • URL / Modifying the SimpleXML directly
    • used, for adding map panel / Adding a map panel using SimpleXML
  • single value
    • about / Introduction
  • single value panel
    • labels, adding to / Adding labels to a single value panel
  • single value visualizations
    • URL / There's more…
  • size
    • scatter chart, using to identify discrete requests / Using a scatter chart to identify discrete requests by size and response time, How to do it..., How it works..., There's more...
  • slowest responding web pages
    • pivoting / Pivoting slowest responding web pages, How to do it..., How it works…
  • Software development kits (SDKs)
    • about / Introduction
  • sort command / Introduction
  • span
    • defining / Defining maximum pause, span, and events in a transaction
  • sparkline
    • about / Introduction
  • Splunk
    • about / Introduction
    • Enterprise / Introduction
    • dashboards / Introduction, Introduction
    • dashboards, for Operational Intelligence / Introduction
    • applications / Introduction
    • lookups, manually adding / Manually adding the lookup to Splunk
    • workflow action, adding manually / Adding a workflow action manually in Splunk
    • alerts / Introduction
    • documentation, URL / There's more…
    • developer website / How it works...
  • Splunk Answers
    • URL / Introduction
  • Splunk app
    • about / Introduction
    • store, URL / Introduction, How to do it…
    • form inputs / Introduction
    • downloading / Downloading and installing a Splunk app
    • installing / Downloading and installing a Splunk app
    • URL / Downloading and installing a Splunk app
  • Splunk Apps site
    • URL / How it works...
  • Splunk Python SDK
    • URL / Getting ready, Getting ready
  • Spunk CLI
    • data files, one-time indexing / One-time indexing of data files via the Splunk CLI
  • stats command / Introduction
    • URL / Searching for the most accessed pages by user
  • Submit button
    • adding, to form / Adding a Submit button to your form
  • success
    • about / Introduction
  • summary index
    • generating search / How it works..., How it works...
    • reporting off / How it works..., How it works...
    • generating, frequently / Generating the summary more frequently
    • overlaps, avoiding / Avoiding summary index overlaps and gaps
    • gaps, avoiding / Avoiding summary index overlaps and gaps
    • backfilling / How it works...
    • backfilling, from within search directly / Backfilling a summary index from within a search directly
    • backfilling, from within search / Backfilling a summary index from within a search directly
  • summary indexing
    • about / Introduction
    • benefits / Introduction

T

  • <tablename>, outputlookup command / How it works...
  • table command / Introduction, How it works...
  • tables
    • drilldown feature, disabling / Disabling the drilldown feature in tables and charts
  • tags
    • about / Defining event types and tags
    • URL / Defining event types and tags
    • defining / How to do it...
    • adding, via tags.conf / Adding event types and tags via eventtypes.conf and tags.conf
  • tags.conf
    • tags, adding via / Adding event types and tags via eventtypes.conf and tags.conf
  • tail command / Introduction
  • Technical Add-Ons (TAs) / Introduction
  • ticket
    • creating, for application errors / Creating a ticket for application errors, How to do it..., How it works...
  • timechart
    • of method requests, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
    • of views, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
    • of response times, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
  • timechart command / Introduction
  • time modifiers
    • about / Introduction
  • time range
    • on search manager, changing / Changing the time range on the search manager
  • time series data points
    • using, with scatter chart / Using time series data points with a scatter chart
  • top-referring websites
    • identifying / Identifying the top-referring websites, How to do it..., There's more…
    • top 10 searching for, instead of top / Searching for the top 10 referring websites using stats instead of top
  • top command / Introduction
  • top error codes
    • pivot charting / Pivot charting top error codes, How it works...
  • top viewed products
    • listing / Listing the top viewed products, How to do it..., There's more...
  • total number of items purchased
    • predicting / Predicting the total number of items purchased
  • total sales transactions
    • pivoting / Pivoting total sales transactions, How to do it...
  • transaction
    • identifying / Introduction
    • grouping / Introduction
    • website visit, starts with / Starts with a website visit, ends with a checkout
    • maximum pause, defining / Defining maximum pause, span, and events in a transaction
    • span, defining / Defining maximum pause, span, and events in a transaction
    • events, defining / Defining maximum pause, span, and events in a transaction
  • transaction command / Introduction, How it works...
    • URL / Defining maximum pause, span, and events in a transaction
  • transaction object constraint / Introduction
  • transaction objects / Introduction
  • transforming command / How it works...
  • trigger conditions
    • about / Introduction
    • per-result / Introduction
    • number of results / Introduction
    • number of hosts / Introduction
    • number of sources / Introduction
    • custom / Introduction
  • triggered alerts
    • viewing, on Splunks Alert manager / Viewing triggered alerts in Splunk's Alert manager
  • type
    • number of method requests, charting / Charting the number of method requests by type and host, How to do it..., How it works...

U

  • unique IP addresses
    • returning, by creating Python application / Creating a Python application to return unique IP addresses, How to do it..., How it works..., There's more...
    • search results, paginating / Paginating the results of your search
  • unique number of visitors
    • displaying / Displaying the unique number of visitors, How to do it..., How it works..., There's more…
  • unique page views
    • REST API, querying remotely / Remotely querying Splunk's REST API for unique page views, How it works..., There's more…
  • Universal Forwarder
    • using, to gather data / Using the Universal Forwarder to gather data, How to do it..., How it works...
  • urgency
    • logic, creating for / Creating logic for urgency

V

  • value
    • based on ranges, coloring / Coloring the value based on ranges
  • views
    • timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., How it works...
    • by host / Method requests, views, and response times by host
  • visitors
    • unique number of visitors, displaying / Displaying the unique number of visitors, How to do it..., How it works...
    • geographical map, displaying / Displaying a geographical map of visitors, How to do it..., How it works...
  • visualizations
    • about / Introduction
    • data, enriching with / Introduction
    • URL / Introduction
    • best practices / Introduction

W

  • web access logs
    • data model, creating for / Creating a data model for web access logs, How to do it..., How it works...
  • web activity
    • searching, form created / Creating a form to search web activities, How to do it..., How it works...
  • web browsers
    • most used web browsers, finding / Finding the most used web browsers, How to do it..., There's more…
    • data for most used OS types, searching / Searching the web browser data for the most used OS types
    • response codes, charting / Charting web page response codes, How it works..., There's more...
  • web framework
    • about / Introduction
  • web hits
    • force-directed graph, adding / Adding a force-directed graph of web hits, How to do it..., How it works...
  • web page activity reports
    • linking, to form / Linking web page activity reports to the form, How to do it..., How it works...
  • web pages
    • most accessed web pages, finding / Finding the most accessed web pages, How to do it..., Searching for the top 10 accessed web pages
    • most accessed pages by user, finding / Searching for the most accessed pages by user
    • response time statistics, displaying / Displaying web page response time statistics, How to do it..., There's more...
    • response time by action, displaying / Displaying web page response time by action
    • most accessed web pages displaying, pie chart used / Using a pie chart to show the most accessed web pages, How to do it..., There's more...
    • top 10 accessed web pages, searching for / Searching for the top 10 accessed web pages
  • web requests
    • relationship, analyzing / Analyzing the relationship of web requests, How to do it..., How it works...
    • abnormally sized web requests, finding / Finding abnormally sized web requests, How to do it..., There's more...
  • website
    • average session time, calculating / Calculating the average session time on a website, How to do it..., How it works...
  • website-traffic volumes
    • predicting / Predicting website-traffic volumes, How to do it..., How it works..., There's more…
  • website visit, transaction
    • starts with / Starts with a website visit, ends with a checkout
  • wget / Getting ready
  • Windows event logs
    • indexing / Indexing the Windows event logs
  • workflow action
    • limiting, by event types / Limiting workflow actions by event types
    • adding manually, in Splunk / Adding a workflow action manually in Splunk
  • workflows
    • about / Lookups