Beruflich Dokumente
Kultur Dokumente
0
Splunk Enterprise Overview
Generated: 10/29/2014 1:10 pm
Table of Contents
Introduction..........................................................................................................1
What's in this manual................................................................................1
About Splunk Enterprise.....................................................................................2
About Splunk Enterprise...........................................................................2
About Splunk Enterprise users..................................................................3
About Splunk Enterprise deployments......................................................4
Splunk Enterprise Resources and Documentation..........................................7
Product resources.....................................................................................7
Splunk Enterprise Administration..............................................................8
Searching and Reporting........................................................................11
Managing Knowledge..............................................................................13
Customize and Extend Splunk Enterprise...............................................15
Troubleshooting......................................................................................16
Introduction
What's in this manual
This manual serves two purposes.
About Splunk Enterprise: Provides a technical overview of Splunk
Enterprise and its users. Discusses the Splunk Enterprise features and
describes the components that make up a Splunk Enterprise deployment.
Splunk Enterprise Resources and Documentation: Provides topics that
help you navigate the documentation based on tasks you want to
complete.
Description
Indexing
Data model
Pivot
Search
Alerts
Reports
Reports are saved searches and pivots. You can run reports on
an ad hoc basis, schedule them to run on a regular interval, set
a scheduled report to generate alerts when the results of their
runs meet particular conditions. Reports can be added to
dashboards as dashboard panels.
Dashboards
Industry Role
Activities
Administrator
network
engineer,
system
administrator
Knowledge
Manager
data analyst,
system
administrator
Search User
data analyst,
IT
professional,
network
engineer,
security
analyst,
system
administrator
Pivot User
business
professional,
data analyst,
executive, IT
professional,
manager,
system
administrator
Developer
system
integrator,
professional
developer
Description
Apps
Forwarder
Indexer
Receiver
Search head
Search peer
For more information about these components and their roles in a distributed
deployment, see "Components and roles" in the Distributed Deployment Manual.
Documentation
What are you looking
for?
Splunk Enterprise
Splunk products
Splunk Apps
Splunk SDKs
Education
What are you looking
for?
Splunk Education
Community
What are you looking
for?
Splunk Answers
#splunk
Look here:
Install Splunk
Upgrade Splunk
Perform backups
Look here:
Look here:
Indexing overview
Manage indexes
Manage indexes
Back up indexes
Archive indexes
Deploy clusters
Configure clusters
Configure clusters
Manage clusters
Manage clusters
Look here:
Forward data
Look here:
Audit Splunk
Searching
The Search Manual discusses how to search and use the search processing
language. See the Search Reference Manual for a catalog of the search
commands with syntax, descriptions, and examples for each command.
Task:
You are new to Splunk Enterprise and
want to learn how to search and use
the search processing language
Look here:
Start with the Search Tutorial
About search
About the search language
11
Creating Pivots
The Knowledge Manager Manual includes a section that discusses how to
design and build data models using the data model editor. The Pivot Manual
discusses how to build pivots tables and charts.
Task:
Look here:
Pivot Tutorial
Reporting
Task:
Use search commands to generate
reports
Learn about the different kinds of
visualizations (tables, charts, event
listings, and so on)
Save a search or pivot as a report
Look here:
About transforming commands and
searches
Visualization Reference
Data structure requirements for
visualizations
Create and edit reports
Accelerate a report
Understand requirements for report
acceleration
Accelerate reports
Schedule a report
Schedule reports
12
Alerting
See how to create and dispatch alerts in the Alerting Manual.
Task:
Look here:
About alerts
Alert Examples
Look here:
Overview of dashboards
Create and edit dashboards via Splunk
Web
Visualization Reference
Data structure requirements for
visualizations
Managing Knowledge
These tables direct you to topics for understanding and managing knowledge
objects such as events, fields, lookups, and data models.
13
Look here:
What is Splunk Enterprise Knowledge?
Look here:
Look here:
About fields
Use default fields
Understand fields
Configure multivalue fields
Define calculated fields
About fields
When Splunk Enterprise extracts fields
Understand and manage field
extractions
14
Look here:
Look here:
Look here:
Logging overview
Logging best practices
REST API Reference
15
Look here:
Look here:
Write custom search commands
Troubleshooting
The Troubleshooting Manual discusses how to analyze activity and diagnose
problems with Splunk Enterprise. You can also look in other manuals to find
specific information. For example, you can find topics on how to improve search
performance in the Search Manual.
Task:
Learn about new features, known
issues, and fixed problems
Learn about Splunk Enterprise
troubleshooting tools
Look here:
What's new in this version
Known issues for this release
Introduction to troubleshooting Splunk
Enterprise
16
17