finding / Finding abnormally sized web requests, How to do it..., There's more...
anomalies command / The anomalies command
anomalousvalues command / The anomalousvalues command
cluster command / The cluster command
abnormal user behavior
alerting on / Alerting on abnormal user behavior, How to do it..., How it works...
abnormal user purchases
without checkouts, alerting on / Alerting on abnormal user purchases without checkouts
abnormal web page response times
alerting on / Alerting on abnormal web page response times, How to do it...
accelerated report
status, viewing / Viewing the status of an accelerated report
acceleration, data model
advanced configuration / Advanced configuration of data model acceleration
acceleration summary information, data model
viewing / Viewing data model and acceleration summary information
activity reports
drilling down on / Dynamically drilling down on activity reports, How to do it..., How it works..., There's more…
alert actions
about / Introduction
e-mail notification / Introduction
script execution / Introduction
RSS notification / Introduction
summary indexing / Introduction
alert manager, alert in / Introduction
alerting
manual, URL / Introduction
on abnormal web page response times / Alerting on abnormal web page response times, How to do it..., How it works..., There's more...
on errors, during checkout in real time / Alerting on errors during checkout in real time, How to do it..., How it works...
on abnormal user behavior / Alerting on abnormal user behavior, How to do it..., How it works...
on abnormal user purchases, without checkouts / Alerting on abnormal user purchases without checkouts
scripted response, on failure / Alerting on failure and triggering a scripted response, How to do it..., How it works..., There's more…
scripted response, on triggering / Alerting on failure and triggering a scripted response, How to do it..., How it works..., There's more…
on predicted sales exceed inventory / Alerting when predicted sales exceed inventory, How to do it..., How it works...
alerts
about / Introduction
scheduled alert / Introduction
per-result alert / Introduction
rolling-window alert / Introduction
triggered alert, viewing in alert manager / Viewing triggered alerts in Splunk's Alert manager
building, via configuration file / Building alerts via a configuration file
RSS feed notification action, adding / Adding an RSS feed notification action to an alert
anomalies command / The anomalies command
anomalousvalues command
about / The anomalousvalues command
URL / The anomalousvalues command
append, outputlookup command / How it works...
append command
URL / There's more…
application
creating, from another application / Creating an application from another application
application errors
ticket, creating for / Creating a ticket for application errors, How to do it..., How it works...
application logs
data model, creating for / Creating a data model for application logs, How to do it..., How it works...
application navigation
customizing / Customizing the application's navigation, How to do it..., How it works..., There's more…
applications
functional performance, charting / Charting the application's functional performance, How to do it..., There's more...
memory usage, charting / Charting the application's memory usage, How to do it..., See also
applications functional statistics
area chart, creating / Creating an area chart of the application's functional statistics, How to do it..., How it works...
area
distributions, mapping by / Mapping different distributions by area
area chart
about / Introduction
of applications functional statistics, creating / Creating an area chart of the application's functional statistics, How to do it..., How it works...
ARIN
searching, for given IP address / Searching ARIN for a given IP address, How to do it..., There's more...
associate command
about / There's more…
Auto-Extracted, object attribute / Introduction
automatic product code lookup
creating / How to do it..., How it works...
average amount spent by category
displaying, bar chart used / Using a bar chart to show the average amount spent by category, How to do it..., How it works...
average execution time
calculating, for multi-tier web requests / Calculating the average execution time for multi-tier web requests, How to do it..., There's more…
calculating, without using join / Calculating the average execution time without using a join
average response time
of function calls, predicting / Predicting the average response time of function calls
average session time
on website, calculating / Calculating the average session time on a website, How to do it..., There's more...
B
backfilling
number of purchases, by city / Backfilling the number of purchases by city, How to do it..., How it works...
summary index / How it works...
summary index, from within search directly / Backfilling a summary index from within a search directly
bar chart
about / Introduction
using, to display average amount spent by category / Using a bar chart to show the average amount spent by category, How to do it..., How it works...
blogs
URL / Getting ready
Boolean operators
AND / Introduction
OR / Introduction
NOT / Introduction
C
calendar heatmap
of product purchases, adding / Adding a calendar heatmap of product purchases, How to do it...
cart additions
percentage from product views, searching / Searching for the percentage of cart additions from product views
category
average amount spent displaying, bar chart used / Using a bar chart to show the average amount spent by category, How to do it...
chart command / Introduction
chart drilldown options
Google search, triggering from / Triggering a Google search from the chart drilldown options
charts
drilldown feature, disabling / Disabling the drilldown feature in tables and charts
checkout, transaction
ends with / Starts with a website visit, ends with a checkout
checkout errors
real-time alert, creating on / Alerting on errors during checkout in real time, How to do it..., How it works...
child object constraint / Introduction
child objects / Introduction
city
number of purchases, backfilling / Backfilling the number of purchases by city, How to do it..., How it works...
CLI
file data input, adding via / Adding a file or directory data input via the CLI
directory data input, adding via / Adding a file or directory data input via the CLI
URL / Adding a file or directory data input via the CLI
network input, adding via / Adding a network input via the CLI
cluster command
about / The cluster command
URL / The cluster command
column chart
about / Introduction
commands
generating / How it works...
reporting / How it works...
streaming / How it works...
Common Information Model (CIM) / Introduction, There's more…
completed transactions
versus hourly count of sessions, calculating / Calculating an hourly count of sessions versus completed transactions, How to do it..., How it works..., There's more...
concurrency command
URL / How it works...
configuration file
alerts, building via / Building alerts via a configuration file
configuration files
URL / How it works..., How it works...
createinapp, outputlookup command / How it works...
create_empty, outputlookup command / How it works...
curl
URL / Getting ready
custom search command
creating, to format product names / Creating a custom search command to format product names, How to do it..., How it works...
custom search commands
generating / How it works...
reporting / How it works...
streaming / How it works...
D
D3.js
URL / How it works..., How it works...
dashboards
for Operational Intelligence / Introduction
adding / Adding dashboards and reports, How to do it..., How it works...
organizing / Organizing the dashboards more efficiently, How to do it..., How it works...
PDF delivery, scheduling / Scheduling the PDF delivery of a dashboard, How to do it..., How it works...
URL / How it works...
data
getting, through network ports / Getting data through network ports, How to do it..., How it works...
gathering, Universal Forwarder used / Using the Universal Forwarder to gather data, How to do it..., There's more...
enriching, with visualizations / Introduction
database connections
total number of database connections, counting / Counting the total number of database connections, How to do it..., How it works...
data files
one-time indexing, via Spunk CLI / One-time indexing of data files via the Splunk CLI
data model
creating, for web access logs / Creating a data model for web access logs, How to do it..., How it works..., There's more...
searching, search interface used / Searching data models using the search interface
accelerating / Accelerating data models, How to do it..., There's more...
acceleration, URL / How it works...
viewing / Viewing data model and acceleration summary information
acceleration summary information, viewing / Viewing data model and acceleration summary information
acceleration, advanced configuration / Advanced configuration of data model acceleration
data model acceleration / Introduction
datamodel command
URL / Searching data models using the search interface
data sources
URL / Introduction
converging / Introduction
data summarization
about / Introduction
methods / Introduction
data summarization, methods
about / Introduction
summary indexing / Introduction
report acceleration / Introduction
data model acceleration / Introduction
DB actions
relationships, analyzing to memory utilization / Analyzing relationships of DB actions to memory utilization
DB Connect
about / Lookups
URL / Looking up inventory from an external database
using, for direct external DB lookups / Use DB Connect for direct external DB lookups
DB lookups, direct external
DB Connect, used for / Use DB Connect for direct external DB lookups
dedup command / Introduction
Developing Views and Apps for Splunk Web manual
URL / There's more...
directories
indexing / Indexing files and directories, How to do it...
directory data input
adding, via CLI / Adding a file or directory data input via the CLI
adding, via inputs.conf / Adding a file or directory input via inputs.conf
distributions
mapping, by area / Mapping different distributions by area
DNS lookups
enabling / Enabling automatic external field lookups
documentation, Splunk
URL / Limiting workflow actions by event types
drilldown feature
disabling, in charts / Disabling the drilldown feature in tables and charts
disabling, in tables / Disabling the drilldown feature in tables and charts
options, URL / Disabling the drilldown feature in tables and charts
drilling down
dynamically, on activity reports / Dynamically drilling down on activity reports, How to do it..., How it works..., There's more…
driver
installing, URL / How to do it…
E
error
about / Introduction
Eval-Expression, object attribute / Introduction
eval command / Introduction
event object constraint / Introduction
event objects / Introduction
events
defining / Defining maximum pause, span, and events in a transaction
event types
about / Defining event types and tags, How it works...
URL / Defining event types and tags
defining / How to do it...
adding, via eventtypes.conf / Adding event types and tags via eventtypes.conf and tags.conf
workflow actions, limiting by / Limiting workflow actions by event types
eventtypes.conf
event types, adding via / Adding event types and tags via eventtypes.conf and tags.conf
existing saved search
modifying, to populate lookup table / Modifying an existing saved search to populate a lookup table
external database
inventory, looking up from / Looking up inventory from an external database, How to do it…, There's more...
external field lookups
automatic external field lookups, enabling / Enabling automatic external field lookups
F
<filename>, outputlookup command / How it works...
field
every field, tabulating / Tabulating every field
removing / Removing fields, then tabulating everything else
field extractions
defining / Defining field extractions, How to do it..., How it works...
fields
working with / Introduction
relationships between, identifying / Introduction
fields command / Introduction
file data input
adding, via CLI / Adding a file or directory data input via the CLI
adding, via inputs.conf / Adding a file or directory input via inputs.conf
files
indexing / Indexing files and directories, How to do it...
filter gauge
about / Introduction
force-directed graph
of web hits, adding / Adding a force-directed graph of web hits, How to do it..., How it works...
form
creating, to search web activity / Creating a form to search web activities, How to do it..., How it works...
Submit button, adding / Adding a Submit button to your form
web page activity reports, linking to / Linking web page activity reports to the form, How to do it..., There's more...
form inputs
Dropdown / Introduction
radio / Introduction
text / Introduction
time / Introduction
function calls
average response time, predicting / Predicting the average response time of function calls
future values
predicting / Introduction
G
gauge
using, to display number of errors / Using a gauge to display the number of errors, How to do it..., How it works...
geographical map
of visitors, displaying / Displaying a geographical map of visitors, How to do it..., How it works...
geographic location
purchases, pivoting by / Pivoting purchases by geographical location, How to do it..., How it works...
Geo IP, object attribute / Introduction
geostats command / Mapping different distributions by area
Google search
triggering, for given reason / Triggering a Google search for a given error, How to do it..., How it works...
triggering, from chart drilldown options / Triggering a Google search from the chart drilldown options
graphical user interface (GUI) / Introduction
H
head command / Introduction
heat map
about / Introduction
High Performance Analytics Store (HPAS) / Introduction
host
number of method requests, charting / Charting the number of method requests by type and host, How to do it..., How it works...
hostnames
adding, to IP addresses / Adding hostnames to IP addresses, How it works..., There's more…
hourly count of sessions
versus completed transactions, calculating / Calculating an hourly count of sessions versus completed transactions, How to do it..., How it works..., There's more...
summary index, generating search / How it works...
summary index, reporting off / How it works...
summary index, generating frequently / Generating the summary more frequently
summary index overlaps, avoiding / Avoiding summary index overlaps and gaps
summary index gaps, avoiding / Avoiding summary index overlaps and gaps
I
inputs.conf
file data input, adding via / Adding a file or directory input via inputs.conf
directory data input, adding via / Adding a file or directory input via inputs.conf
network input, adding via / Adding a network input via inputs.conf
inventory
looking up, from external database / Looking up inventory from an external database, How to do it…, There's more...
IP addresses
suspect IP addresses, flagging / Flagging suspicious IP addresses, How to do it..., How it works...
malicious IP addresses, lookup table creating for / How to do it..., How it works...
hostnames, adding / Adding hostnames to IP addresses, How it works..., There's more…
ARIN, searching for / Searching ARIN for a given IP address, How to do it..., How it works...
item views
line chart, creating / Creating a line chart of item views and purchases over time, How to do it…
J
Java Bridge Server / How it works...
Java Virtual Machine (JVM) / How it works...
join
URL / There's more…
K
Knowledge Manager documentation
URL / Introduction
L
labels
adding, to single value pack / Adding labels to a single value panel
line chart
about / Introduction
of item views, creating / Creating a line chart of item views and purchases over time, How to do it…
of purchases over time, creating / Creating a line chart of item views and purchases over time, How to do it…
logic
creating, for urgency / Creating logic for urgency
Lookup, object attribute / Introduction
lookup command / Introduction
lookups
about / Lookups
manually, adding to Splunk / Manually adding the lookup to Splunk
lookup table
of malicious IP addresses, creating / How to do it..., How it works...
populating, existing saved search used / Modifying an existing saved search to populate a lookup table
M
map
about / Introduction
map panel
adding, SimpleXML used / Adding a map panel using SimpleXML
marker gauge
about / Introduction
max, outputlookup command / How it works...
maximum concurrent checkouts
displaying / Displaying the maximum concurrent checkouts, How to do it..., How it works...
maximum number of concurrent sessions over time
displaying / Displaying the maximum number of concurrent sessions over time, How to do it..., How it works...
maximum pause
defining / Defining maximum pause, span, and events in a transaction
method requests
timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., How it works...
by host / Method requests, views, and response times by host
modular inputs
using / Using modular inputs, How to do it..., There's more...
monitor input type
about / How it works...
multi-tier web requests
average execution time, calculating / Calculating the average execution time for multi-tier web requests, How to do it..., There's more…
N
NAT (Network Address Translation) / How it works...
network input
adding, via CLI / Adding a network input via the CLI
adding, via inputs.conf / Adding a network input via inputs.conf
network ports
data, getting through / Getting data through network ports, How to do it..., How it works..., There's more...
number of errors
displaying, gauge used / Using a gauge to display the number of errors, How to do it..., There's more…
number of method requests
charting, by type / Charting the number of method requests by type and host, How to do it..., How it works...
charting, by host / Charting the number of method requests by type and host, How to do it..., How it works...
number of purchases
by city. backfilling / Backfilling the number of purchases by city, How to do it..., How it works..., There's more...
summary index, generating search / How it works...
summary index, backfilling / How it works...
O
object attributes
Auto-Extracted / Introduction
Eval-Expression / Introduction
Lookup / Introduction
Regular Expression / Introduction
Geo IP / Introduction
object constraint
event object constraint / Introduction
search object constraint / Introduction
transaction object constraint / Introduction
child object constraint / Introduction
object types
event objects / Introduction
search objects / Introduction
transaction objects / Introduction
child objects / Introduction
one-time indexing
of data files, via Spunk CLI / One-time indexing of data files via the Splunk CLI
OpenStreetMap service
URL / How it works...
Operational Intelligence application
creating / Creating an Operational Intelligence application, How to do it..., How it works...
creating, from another application / Creating an application from another application
Operational Intelligence dashboard
creating / Creating an Operational Intelligence dashboard, How to do it..., There's more...
adding / Adding dashboards and reports, How to do it..., How it works...
scheduling, URL / How it works...
response codes
web page response codes, charting / Charting web page response codes, How it works..., There's more...
error web page response codes, totaling / Totaling success and error web page response codes
success web page response codes, totaling / Totaling success and error web page response codes
response times
timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more..., Method requests, views, and response times by host
by host / Method requests, views, and response times by host
scatter chart, using to identify discrete requests / Using a scatter chart to identify discrete requests by size and response time, How to do it..., How it works..., There's more...
response time statistics, web page
displaying / Displaying web page response time statistics, How to do it..., There's more...
REST API
about / Introduction
for unique page views, querying remotely / Remotely querying Splunk's REST API for unique page views, How to do it..., How it works...
REST Wikipedia page
URL / How it works...
rolling-window alert / Introduction
RSS feed notification action
adding, to alert / Adding an RSS feed notification action to an alert
S
sales
predicted sales exceed inventory, alerting on / Alerting when predicted sales exceed inventory, How to do it..., How it works...
sample data
loading / Loading the sample data for this book, How to do it..., How it works...
saved reports
permissions, changing / Changing the permissions of saved reports
saved searches
about / Introduction
scatter chart
about / Introduction
using, to identify discrete requests by size / Using a scatter chart to identify discrete requests by size and response time, How to do it..., There's more...
using, to identify discrete requests by response time / Using a scatter chart to identify discrete requests by size and response time, How to do it..., There's more...
time series data points, using with / Using time series data points with a scatter chart
time series data points, using / Using time series data points with a scatter chart
scheduled alert / Introduction
scripted inputs
using / Using scripted inputs, How to do it..., How it works...
scripted response
failure, alerting on / Alerting on failure and triggering a scripted response, How to do it..., There's more…
triggering, alerting on / Alerting on failure and triggering a scripted response, How to do it..., There's more…
search
results, paginating / Paginating the results of your search
search command / Introduction
searches
about / Introduction
saving / Introduction
searching
pivoting, pivot command used / Pivot searching using the pivot command and search interface
pivoting, search interface used / Pivot searching using the pivot command and search interface
search interface
used, for searching data model / Searching data models using the search interface
creating, for application logs / Creating a data model for application logs, How to do it..., How it works...
used, for pivot searching / Pivot searching using the pivot command and search interface
search manager
time range, changing / Changing the time range on the search manager
search object constraint / Introduction
search objects / Introduction
Search Processing Language (SPL) / Introduction, Introduction
about / Introduction
Sessions Over Time chart
overlay, adding / Adding an overlay to the Sessions Over Time chart
session state table
creating / Creating a session state table, How to do it..., How it works...
session token
authenticating with / Authenticating with a session token
SimpleXML
about / Introduction
modifying / Modifying the SimpleXML directly
URL / Modifying the SimpleXML directly
used, for adding map panel / Adding a map panel using SimpleXML
single value
about / Introduction
single value panel
labels, adding to / Adding labels to a single value panel
single value visualizations
URL / There's more…
size
scatter chart, using to identify discrete requests / Using a scatter chart to identify discrete requests by size and response time, How to do it..., How it works..., There's more...
slowest responding web pages
pivoting / Pivoting slowest responding web pages, How to do it..., How it works…
Software development kits (SDKs)
about / Introduction
sort command / Introduction
span
defining / Defining maximum pause, span, and events in a transaction
sparkline
about / Introduction
Splunk
about / Introduction
Enterprise / Introduction
dashboards / Introduction, Introduction
dashboards, for Operational Intelligence / Introduction
applications / Introduction
lookups, manually adding / Manually adding the lookup to Splunk
workflow action, adding manually / Adding a workflow action manually in Splunk
alerts / Introduction
documentation, URL / There's more…
developer website / How it works...
Splunk Answers
URL / Introduction
Splunk app
about / Introduction
store, URL / Introduction, How to do it…
form inputs / Introduction
downloading / Downloading and installing a Splunk app
installing / Downloading and installing a Splunk app
URL / Downloading and installing a Splunk app
Splunk Apps site
URL / How it works...
Splunk Python SDK
URL / Getting ready, Getting ready
Spunk CLI
data files, one-time indexing / One-time indexing of data files via the Splunk CLI
stats command / Introduction
URL / Searching for the most accessed pages by user
Submit button
adding, to form / Adding a Submit button to your form
success
about / Introduction
summary index
generating search / How it works..., How it works...
reporting off / How it works..., How it works...
generating, frequently / Generating the summary more frequently
overlaps, avoiding / Avoiding summary index overlaps and gaps
gaps, avoiding / Avoiding summary index overlaps and gaps
backfilling / How it works...
backfilling, from within search directly / Backfilling a summary index from within a search directly
backfilling, from within search / Backfilling a summary index from within a search directly
summary indexing
about / Introduction
benefits / Introduction
T
<tablename>, outputlookup command / How it works...
table command / Introduction, How it works...
tables
drilldown feature, disabling / Disabling the drilldown feature in tables and charts
tags
about / Defining event types and tags
URL / Defining event types and tags
defining / How to do it...
adding, via tags.conf / Adding event types and tags via eventtypes.conf and tags.conf
tags.conf
tags, adding via / Adding event types and tags via eventtypes.conf and tags.conf
tail command / Introduction
Technical Add-Ons (TAs) / Introduction
ticket
creating, for application errors / Creating a ticket for application errors, How to do it..., How it works...
timechart
of method requests, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
of views, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
of response times, creating / Creating a timechart of method requests, views, and response times, How to do it..., There's more...
timechart command / Introduction
time modifiers
about / Introduction
time range
on search manager, changing / Changing the time range on the search manager
time series data points
using, with scatter chart / Using time series data points with a scatter chart
top-referring websites
identifying / Identifying the top-referring websites, How to do it..., There's more…
top 10 searching for, instead of top / Searching for the top 10 referring websites using stats instead of top
top command / Introduction
top error codes
pivot charting / Pivot charting top error codes, How it works...
top viewed products
listing / Listing the top viewed products, How to do it..., There's more...
total number of items purchased
predicting / Predicting the total number of items purchased
total sales transactions
pivoting / Pivoting total sales transactions, How to do it...
transaction
identifying / Introduction
grouping / Introduction
website visit, starts with / Starts with a website visit, ends with a checkout
maximum pause, defining / Defining maximum pause, span, and events in a transaction
span, defining / Defining maximum pause, span, and events in a transaction
events, defining / Defining maximum pause, span, and events in a transaction
transaction command / Introduction, How it works...
URL / Defining maximum pause, span, and events in a transaction
transaction object constraint / Introduction
transaction objects / Introduction
transforming command / How it works...
trigger conditions
about / Introduction
per-result / Introduction
number of results / Introduction
number of hosts / Introduction
number of sources / Introduction
custom / Introduction
triggered alerts
viewing, on Splunks Alert manager / Viewing triggered alerts in Splunk's Alert manager
type
number of method requests, charting / Charting the number of method requests by type and host, How to do it..., How it works...
U
unique IP addresses
returning, by creating Python application / Creating a Python application to return unique IP addresses, How to do it..., How it works..., There's more...
search results, paginating / Paginating the results of your search
unique number of visitors
displaying / Displaying the unique number of visitors, How to do it..., How it works..., There's more…
unique page views
REST API, querying remotely / Remotely querying Splunk's REST API for unique page views, How it works..., There's more…
Universal Forwarder
using, to gather data / Using the Universal Forwarder to gather data, How to do it..., How it works...
urgency
logic, creating for / Creating logic for urgency
V
value
based on ranges, coloring / Coloring the value based on ranges
views
timechart, creating / Creating a timechart of method requests, views, and response times, How to do it..., How it works...
by host / Method requests, views, and response times by host
visitors
unique number of visitors, displaying / Displaying the unique number of visitors, How to do it..., How it works...
geographical map, displaying / Displaying a geographical map of visitors, How to do it..., How it works...
visualizations
about / Introduction
data, enriching with / Introduction
URL / Introduction
best practices / Introduction
W
web access logs
data model, creating for / Creating a data model for web access logs, How to do it..., How it works...
web activity
searching, form created / Creating a form to search web activities, How to do it..., How it works...
web browsers
most used web browsers, finding / Finding the most used web browsers, How to do it..., There's more…
data for most used OS types, searching / Searching the web browser data for the most used OS types
response codes, charting / Charting web page response codes, How it works..., There's more...
web framework
about / Introduction
web hits
force-directed graph, adding / Adding a force-directed graph of web hits, How to do it..., How it works...
web page activity reports
linking, to form / Linking web page activity reports to the form, How to do it..., How it works...
web pages
most accessed web pages, finding / Finding the most accessed web pages, How to do it..., Searching for the top 10 accessed web pages
most accessed pages by user, finding / Searching for the most accessed pages by user
response time statistics, displaying / Displaying web page response time statistics, How to do it..., There's more...
response time by action, displaying / Displaying web page response time by action
most accessed web pages displaying, pie chart used / Using a pie chart to show the most accessed web pages, How to do it..., There's more...
top 10 accessed web pages, searching for / Searching for the top 10 accessed web pages
web requests
relationship, analyzing / Analyzing the relationship of web requests, How to do it..., How it works...
abnormally sized web requests, finding / Finding abnormally sized web requests, How to do it..., There's more...
website
average session time, calculating / Calculating the average session time on a website, How to do it..., How it works...
website-traffic volumes
predicting / Predicting website-traffic volumes, How to do it..., How it works..., There's more…
website visit, transaction
starts with / Starts with a website visit, ends with a checkout
wget / Getting ready
Windows event logs
indexing / Indexing the Windows event logs
workflow action
limiting, by event types / Limiting workflow actions by event types
adding manually, in Splunk / Adding a workflow action manually in Splunk