Data Analytics Using Splunk 9.x

Book description

Make the most of Splunk 9.x to build insightful reports and dashboards with a detailed walk-through of its extensive features and capabilities

Key Features

  • Be well-versed with the Splunk 9. x architecture, installation, onboarding, and indexing data features
  • Create advanced visualizations using the Splunk search processing language
  • Explore advanced Splunk administration techniques, including clustering, data modeling, and container management

Book Description

Splunk 9 improves on the existing Splunk tool to include important features such as federated search, observability, performance improvements, and dashboarding. This book helps you to make the best use of the impressive and new features to prepare a Splunk installation that can be employed in the data analysis process.

Starting with an introduction to the different Splunk components, such as indexers, search heads, and forwarders, this Splunk book takes you through the step-by-step installation and configuration instructions for basic Splunk components using Amazon Web Services (AWS) instances. You’ll import the BOTS v1 dataset into a search head and begin exploring data using the Splunk Search Processing Language (SPL), covering various types of Splunk commands, lookups, and macros. After that, you’ll create tables, charts, and dashboards using Splunk’s new Dashboard Studio, and then advance to work with clustering, container management, data models, federated search, bucket merging, and more.

By the end of the book, you’ll not only have learned everything about the latest features of Splunk 9 but also have a solid understanding of the performance tuning techniques in the latest version.

What you will learn

  • Install and configure the Splunk 9 environment
  • Create advanced dashboards using the flexible layout options in Dashboard Studio
  • Understand the Splunk licensing models
  • Create tables and make use of the various types of charts available in Splunk 9.x
  • Explore the new configuration management features
  • Implement the performance improvements introduced in Splunk 9.x
  • Integrate Splunk with Kubernetes for optimizing CI/CD management

Who this book is for

The book is for data analysts, Splunk users, and administrators who want to become well-versed in the data analytics services offered by Splunk 9. You need to have a basic understanding of Splunk fundamentals to get the most out of this book.

Table of contents

  1. Data Analytics Using Splunk 9.x
  2. Contributors
  3. About the author
  4. About the reviewers
  5. Preface
    1. Who this book is for
    2. What this book covers
    3. To get the most out of this book
    4. Download the example code files
    5. Conventions used
    6. Get in touch
    7. Share Your Thoughts
    8. Download a free PDF copy of this book
  6. Part 1: Getting Started with Splunk
  7. Chapter 1: Introduction to Splunk and its Core Components
    1. Splunking big data
      1. How is big data generated?
      2. Understanding Splunk
    2. Exploring Splunk components
      1. Forwarders
      2. Indexers
      3. Search heads
    3. Introducing the case study – splunking the 
BOTS Dataset v1
      1. The setup
    4. Summary
  8. Chapter 2: Setting Up the Splunk Environment
    1. Technical requirements
    2. Installing Splunk Enterprise
      1. Deploying AWS EC2 instances with the Splunk Enterprise AMI
      2. Deploying AWS EC2 instances with the Windows Server 19 Base AMI
    3. Setting up Splunk forwarders
    4. Setting up Splunk deployment servers
    5. Setting up Splunk indexers
    6. Setting up Splunk search heads
    7. Installing additional Splunk add-ons and apps
      1. Installing the BOTS Dataset v1 app
    8. Managing access to Splunk
      1. Users
    9. Summary
  9. Chapter 3: Onboarding and Normalizing Data
    1. Exploring inputs.conf using the Splunk Add-on for Microsoft Windows
      1. Understanding the filesystem of a Splunk add-on
      2. Exploring inputs.conf
      3. Extracting fields using Splunk Web
      4. Field aliases
      5. Calculated fields
      6. Field extractions
    2. Extracting fields using props.conf and transforms.conf
    3. Creating event types and tagging
    4. Summary
  10. Part 2: Visualizing Data with Splunk
  11. Chapter 4: Introduction to SPL
    1. Understanding the Splunk search interface
    2. Dissecting a Splunk query
    3. Formatting and transforming data
      1. Simple mathematical functions
    4. Summary
  12. Chapter 5: Reporting Commands, Lookups, and Macros
    1. Exploring more Splunk commands
      1. Streaming commands
      2. Generating commands
      3. Transforming commands
      4. Orchestrating commands
      5. Dataset processing commands
      6. join
    2. Enhancing logs with lookups
    3. Simplifying Splunk searches with macros
    4. Summary
  13. Chapter 6: Creating Tables and Charts Using SPL
    1. Creating and formatting tables
    2. Creating and formatting charts
    3. Creating advanced charts
      1. Scatter plots
      2. Bubble charts
      3. Choropleth maps
    4. Summary
  14. Chapter 7: Creating Dynamic Dashboards
    1. Adding tables and charts to dashboards
      1. Editing a dashboard panel
    2. Adding inputs, tokens, and drilldowns
      1. Creating dropdown inputs
      2. Adding a time picker
    3. Exploring the dashboard source
    4. Adding reports and drilldowns to dashboards
    5. Experimenting with the new Dashboard Studio
    6. Summary
  15. Part 3: Advanced Topics in Splunk
  16. Chapter 8: Licensing, Indexing, and Buckets
    1. Understanding Splunk indexing and buckets
    2. Exploring Splunk queues
      1. Parsing
      2. Indexing
    3. Discussing Splunk licensing models
      1. Configuring licenses
    4. Summary
  17. Chapter 9: Clustering and Advanced Administration
    1. Introducing Splunk clusters
    2. Understanding search head clusters
      1. Configuring a search head cluster
    3. Understanding indexer clusters
      1. Replication factor
      2. Configuring indexer clusters
    4. Summary
  18. Chapter 10: Data Models, Acceleration, and Other Ways to Improve Performance
    1. Understanding data models
      1. Lookups
      2. Table datasets
      3. Data model datasets
    2. Accelerating data models
      1. Understanding the tstats command
      2. Exploring the Splunk CIM add-on
    3. Improving performance
    4. Summary
  19. Chapter 11: Multisite Splunk Deployments and Federated Search
    1. Exploring multisite Splunk deployments
      1. Splunk Cloud Platform
      2. Multisite search deployments
      3. Hybrid search
    2. Configuring federated search
    3. Using federated search
      1. Searching remote indexes
      2. Searching remote saved searches
      3. Searching remote data models
    4. Summary
  20. Chapter 12: Container Management
    1. Understanding container management
    2. Deploying Splunk in Docker
    3. Getting started with Splunk Operator for Kubernetes
    4. Exploring container logs using Splunk
    5. Summary
  21. Index
    1. Why subscribe?
  22. Other Books You May Enjoy
    1. Packt is searching for authors like you
    2. Share Your Thoughts
    3. Download a free PDF copy of this book

Product information

  • Title: Data Analytics Using Splunk 9.x
  • Author(s): Dr. Nadine Shillingford
  • Release date: January 2023
  • Publisher(s): Packt Publishing
  • ISBN: 9781803249414