Visão Geral
O Curso Splunk Engineering Intermediate, foi projetado para indivíduos que já possuem conhecimento básico da arquitetura Splunk, bem como da Splunk Processing Language (SPL). Este Curso Splunk Engineering Intermediate baseia-se no seu conhecimento do Splunk Engineering Beginner e apresenta conceitos e terminologias mais profundos do Splunk.
O que vou aprender?
- Neste Curso Splunk Engineering Intermediate, você se tornará um desenvolvedor de objetos de conhecimento completo no Splunk. Você aprenderá novos comandos de pesquisa e relatório de SPL, criará objetos de conhecimento, usará aliases de campo e campos calculados, criará tags e tipos de eventos, usará macros, criará ações de fluxo de trabalho e modelos de dados e normalizará dados com o Common Information Model no Splunk Enterprise ou plataformas Splunk Cloud.
Conteúdo Programatico
Beyond Search Fundamentals
- Review Basic Search Commands
- Use Case correctly in Searches
- Describe Splunk’s Search Process
Commands for Visualizations
- Explore Data Structure Requirements
- Explore Visualization Types
- Create and Format Charts
- Create and Format Timecharts
- Explain when to use each type of Reporting Command
Advanced Visualizations
- Create a Trendline
- Create Maps
- Create and Format Single Values
- Using the addtotals Command
Filtering and Formatting Data
- Using the eval Command
- Using the search and where Commands to Filter Calculated Results
- Using fillnull Command
Correlating Events
- Identify transactions
- Group events using fields
- Group events using fields and time
- Search with transactions
- Report on transactions
- Determine when to use transaction vs. stats
Introduction to Knowledge Objects
- Identify the Categories of Knowledge Objects
- Define the role of a Knowledge Manager
- Identify Naming Conventions
- Review Permissions
- Manage Knowledge Objects
- Describe the Splunk Common Information Model (CIM)
Creating and Managing Fields
- Review the Field Extractor (FX) Methods
- Identify the Different Options to get to the Field Extractor
- Review the Process of Extracting fields Manually Using Regular Expressions
- Use the Field Extraction Manager to Modify Extracted fields
Creating Field Aliases and Calculated Fields
- Create and Use Field Aliases
- Create Calculated Fields
Creating Tags and Event Types
- Create and Use Tags
- Describe Event Types and their Uses
- Create an Event Type
Creating and Using Macros
- Describe Macros
- Manage Macros
- Create a Basic Macro
- Use a Basic Macro
- Define Arguments and Variables for a Macro
- Add and Use Arguments with a Macro
Creating and Using Workflow Actions
- Create a GET Workflow Action
- Create a POST Workflow Action
- Create a Search Workflow Action
Creating Data Models
- Describe the Relationship between Data Models and Pivot
- Identify Data Model Datasets
- Identify Dataset Fields
- Create a Data Model
- Use a Data Model in Pivot
Using the Common Information Model (CIM) Add-On
- Describe the Splunk Common Information Model
- List the Knowledge Objects Included with the Splunk CIM Add-On
- Use the CIM Add-On to Normalize Data