Splunk Ppt satinder singh sandhu

  • View
    221

  • Download
    0

Embed Size (px)

Text of Splunk Ppt satinder singh sandhu

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    1/146

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    2/146

    Course-Ware

    -> Introduction

    -> Splunk Inc

    -> Licensing

    -> Installation

    -> Login

    -> Splunk Home-> Getting Data

    -> Search Dashboard

    -> Data Summary 

    -> Search Actions and Modes

    -> Search Language

    -> Using Sub search -> ield Lookups

    -> Sa!ing and Sharing "eports

    -> More Searches and "eports

    -> #reating Dashboards

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    3/146

    INTRODUCTION

    Splunk $nterprise is the leading plat%orm %or real-time operational intelligence& It's the easy( %ast and secure  )ay to search( analy*e and !isuali*e the massi!e streams o% machine data generated by your I+ systems and

    technology in%rastructure,physical( !irtual and in the cloud&

    +roubleshoot application problems and in!estigate security incidents in minutes instead o% hours or days( a!oid ser!ice degradation or outages( deli!er compliance at lo)er cost and gain ne) business insights

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    4/146

    INTRODUCTION

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    5/146

    INTRODUCTION

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    6/146

    SPLUNK INC.

    ounded in ../ and head0uartered in San rancisco( #ali%ornia

    Specialties – “Machine Data +o 1perational Intelligence2 3

    +he machine data that %acilitates operational intelligence comes in many di%%erent %rom many di%%erent sources& Splunk is able to collect and inde4 data

    %rom many di%%erent sources( including log%iles )ritten by )eb ser!ers or  business applications( syslog data streaming in %rom net)ork de!ices( or the output o% custom de!eloped scripts&

    Searching( monitoring( and analy*ing machine-generated big data( !ia a )eb-style inter%ace

     According to tech target( Splunk is designated as the SI$M o% the year&

    +he name 5Splunk5 is a re%erence to e4ploring ca!es( as in spelunking&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    7/146

    SPLUNK – LICENSING

     6ou'll get a Splunk $nterprise REE license %or 7. days and you can inde4 up to 8.. megabytes o% data per day&

    Perpetual a!" Ter# Lice!si!$

    +here are t)o options %or licensing Splunk $nterprise9 :erpetual license9 this includes the %ull %unctionality o% Splunk $nterprise and starts as lo) as ;

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    8/146

    SPLUNK – LICENSING

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    9/146

    INST%LL%TION

    Li!u& installation instructions

      tar 4!*% splunkBpackageBname&tg* -# ?opt

     Wi!"o's installation instructions

    =& +o start the installer( double-click the splunk&msi %ile& & In the Celcome panel( click e4t&

    /& In #ustomer In%ormation( enter the re0uested details and click e4t&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    10/146

    INST%LL%TION

    (ac OS ) i!stallatio! i!structio!s

    =& a!igate to the %older or directory )here the installer is located&

    & Double-click on the DMG %ile&

    /& Double-click on splunk&pkg&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    11/146

    Users

     About Splunk $nterprise users

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    12/146

    Users

     About Splunk $nterprise users

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    13/146

    irst ti#e Lo$i!

    +he Splunk inter%ace is )eb-based( )hich means that no client needs to be installed&

    http9??localhost9...

    irst time signing credentials

    Username 3 admin

      :ass)ord - changeme

    It is a good idea to change this pass)ord to pre!ent un)anted changes to your deployment&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    14/146

    Splu!* +o#e

     %pps

    +he Apps panel lists the apps that are installed on your Splunk instance that you ha!e permission to !ie)& Select the app %rom the list to open it&

      or an out-o%-the-bo4 Splunk $nterprise installation( you see one App in the )orkspace9 Search F "eporting& Chen you ha!e more than one app( you can drag and drop the apps )ithin the )orkspace to rearrange them&

     6ou can do t)o actions on this panel9 - #lick the gear icon to !ie) and manage the apps that are installed in your Splunk instance&

      - #lick the plus icon to bro)se %or more apps to install&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    15/146

    Splu!* +o#e

    Splunk ar

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    16/146

    Splu!* +o#e

    Setti!$s #e!u

    +he Settings menu lists the con%iguration pages %or no)ledge obects( Distributed en!ironment settings( System and licensing( Data( and Authentication settings& I% you do not see some o% these

    options( you do not ha!e the permissions to !ie) or edit them&

    User #e!u

    +he User menu here is called 5Administrator5 because that is the de%ault user name %or a ne) installation& 6ou can change this display name by selecting $dit account and changing the ull name& 6ou can also edit the time *one settings( select a de%ault app %or this account( and change the account's pass)ord& +he User menu is also )here you Logout o% this Splunk installation&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    17/146

    Splu!* +o#e

    (essa$es #e!u

     All system-le!el error messages are listed here& Chen there is a ne) message to re!ie)( a noti%ication displays as a count ne4t to the Messages menu&

     %cti,it #e!u

    -#lick obs to open the search obs manager )indo)( )here  you can !ie) and manage currently running searches&

    -#lick +riggered Alerts to !ie) scheduled alerts that are

    triggered& +his tutorial does not discuss sa!ing and scheduling alerts&

    -#lick System Acti!ity to see Dashboards about user acti!ity and status o% the system&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    18/146

    GETTING D%T% 

     A Splunk data repository is called an inde4& During inde4ing Jor e!ent processingK( Splunk processes the incoming data stream to enable %ast search and analysis( storing the results in the inde4 as e!ents&

    $!ents are stored in the inde4 as a group o% %iles that %all into t)o categories9

    - "a)data( )hich is the ra) data in a compressed %orm&

      - Inde4 %iles and some metadata %iles that point to the ra) data&

    +hese %iles reside in sets o% directories( called buckets( organi*ed  by age&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    19/146

    GETTING D%T% 

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    20/146

    SE%RC+ D%S+O%RD

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    21/146

    D%T% SU((%R/

    +he Data Summary dialogue displays three tabs9 Hosts( Sources( Sourcetypes&

    +he host o% an e!ent is the host name( I: address( or %ully 0uali%ied domain name o% the net)ork machine %rom )hich the e!ent originated&

    +he source o% an e!ent is the %ile or directory path( net)ork port( or script %rom )hich the e!ent originated&

    +he source type o% an e!ent tells you )hat kind o% data it is( usually based on ho) it is %ormatted& +his classi%ication lets you search %or the same type o% data across multiple sources and hosts&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    22/146

    D%T% SU((%R/

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    23/146

    +ime "ange :icker

    y de%ault( the time range %or a search is set to All time& Chen  you search large !olumes o% data( results return %aster )hen you run the search o!er a smaller time period&

    I% one o% the :resets is not )hat you )ant( you can de%ine a

    custom time range( such as a "elati!e time range or a Date F +ime "ange&

    +o run a search o!er the last t)o hours( use the "elati!e time range option&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    24/146

    +ime "ange :icker

    or e4ample( to troubleshoot an issue that took place September /.th at 9

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    25/146

    Search Actions and Modes

    #ontrol search ob progress  A%ter you launch a search( you can pause it and stop it using the buttons under the search bar& Also( you can access and manage in%ormation about the

    search's ob )ithout lea!ing the Search page&

  • 8/15/2019 Splunk Ppt satinder singh sandhu

    26/146

    Search Actions and Modes

    #lick ob and choose %rom the a!ailable options there&

    - E"it 0o1 setti!$s. Select this option to open the ob Settings di