-
Course
- Core Tech
Advanced Searching and Reporting with Splunk Enterprise
This course will teach you different searching and reporting techniques used to address complex data analysis and reporting problems. It will also focus on developing robust, optimal and efficient searches.
What you'll learn
Splunk is a data analysis and aggregation tool that utilizes a multitude of techniques for data analysis and reporting. The end goal of having a Splunk infrastructure in place is to correlate and analyze the data and derive useful insights for forecasting, capacity planning, and decision making as well as security incident management. In this course, Advanced Searching and Reporting with Splunk Enterprise, you’ll learn different methods and techniques to correlate, search, and analyze data to answer complex questions thus helping management at all tiers in risk mitigation, incident response, forecasting, and decision making. First, you’ll explore different techniques for search optimization and writing efficient queries using Search Processing Language. Next, you’ll discover how to manipulate and filter data in Splunk Enterprise. Finally, you’ll learn how to combine searches, use sub-searches, and leverage advanced transactions. When you’re finished with this course, you’ll have the skills and knowledge needed to create optimal and efficient searches and reports and solve complex data analysis problems using advanced analytics through SPL commands.
Table of contents
- Overview | 1m 48s
- Data Handling and Search Process in Splunk Enterprise | 3m 51s
- What Is Inside a Bucket? | 2m 17s
- Event Segmentation for Keyword Searching | 1m 15s
- Working and Use of Bloom Filters in Splunk Enterprise | 3m 3s
- Types of SPL Commands | 3m 14s
- Ensuring Search Efficiency and Search Optimization | 5m 46s
- Demo: Using the Job Inspector for Troubleshooting and Monitoring Search Performance | 4m 34s
- Summary | 43s
About the author
Muhammad Awan is a Senior Splunk Admin in working in Public Sector. Has been associated with Splunk and data science related technologies for a decade. Splunk Certified Admin and Splunk Certified Power User. Microsoft Certified Solutions Exert and Microsoft Certified Solutions Associate (Office 365) MCSA (Messaging).
More Courses by Muhammad