Visão Geral
O curso de formação Splunk Fundamentals 2 centra-se na pesquisa e relato de comandos, bem como na criação de objetos de conhecimento, utilizando comandos e visualizações transformadoras, filtrando e formatando resultados, correlacionando eventos, criando objetos de conhecimento, utilizando alias de campo e campos calculados, criando etiquetas e tipos de eventos, utilizando macros, criando ações de fluxo de trabalho e modelos de dados, e normalizando dados com o Modelo de Interface Comum (CIM).
Conteúdo Programatico
Introduction
- Overview of Buttercup Games Inc.
- Lab environment
Beyond Search Fundamentals
- Search fundamentals review
- Case sensitivity
- Using the job inspector to view search performance
Using Transforming Commands for Visualizations
- Explore data structure requirements
- Explore visualization types
- Create and format charts and timecharts
Using Mapping and Single Value Commands
- The iplocation command
- The geostats command
- The geom command
- The geom command
Filtering and Formatting Results
- The eval command
- Using the search and where commands to filter results
- The filnull command
Correlating Events
- Identify transactions
- Group events using fields
- Group events using fields and time
- Search with transactions
- Report on transactions
- Determine when to use transactions vs. stats
Introduction to Knowledge Objects
- Identify naming conventions
- Review permissions
- Manage knowledge objects
Creating and Managing Fields
- Perform regex field extractions using the Field Extractor (FX)
- Perform delimiter field extractions using the FX
Creating Field Aliases and Calculated Fields
- Describe, create, and use field aliases
- Describe, create and use calculated fields
Creating Tags and Event Types
- Create and use tags
- Describe event types and their uses
- Create an event type
Creating and Using Macros
- Describe macros
- Create and use a basic macro
- Define arguments and variables for a macro
- Add and use arguments with a macro
Creating and Using Workflow Actions
- Describe the function of GET, POST, and Search workflow actions
- Create a GET workflow action
- Create a POST workflow action
- Create a Search workflow action
Creating Data Models
- Describe the relationship between data models and pivot
- Identify data model attributes
- Create a data model
- Create a data model
Using the Common Information Model (CIM) Add-On
- Describe the Splunk CIM
- List the knowledge objects included with the Splunk CIM Add-On
- Use the CIM Add-On to normalize data