Introduction to Splunk
"Hands On" Workshop Can't make these dates? Join our webinar instead:
|
Introduction to Splunk "Hands on" Workshop
|
Feature
|
Description
|
Indexing
|
Splunk indexes machine data. This includes data streaming from packaged and custom applications, application servers, web servers, databases, networks, virtual machines, telecoms equipment, operating system, sensors and so on, that make up your IT infrastructure. The maximum indexing volume depends on the Splunk Enterprise License.
|
Search
|
Search is the primary way users navigate data in Splunk Enterprise. You can write a search to retrieve events from an index, use statistical commands to calculate metrics and generate reports, search for specific conditions within a rolling time window, identify patterns in your data, predict future trends, and so on. Searches can be saved as reports and used to power dashboard panels.
|
Alerts
|
Alerts are triggered when conditions are met by search results for both historical and real-time searches. Alerts can be configured to trigger actions such as sending alert information to designated email addresses, post alert information to an RSS feed, and run a custom script, such as one that posts an alert event to syslog.
|
Reports
|
Reports are saved searches and pivots. You can run reports on an ad hoc basis, schedule them to run on a regular interval, set a scheduled report to generate alerts when the results of their runs meet particular conditions. Reports can be added to dashboards as dashboard panels.
|
Dashboards
|
Dashboards are made up of panels that contain modules such as search boxes, fields, charts, tables, forms, and so on. Dashboard panels are usually hooked up to saved searches or pivots. They can display the results of completed searches as well as data from backgrounded real-time searches.
|