学习Splunk Fundamentals Part 2 (IOD) 和 Splunk Fundamentals Part 1课程的笔记。

    1. Chart

      1. Over

      2. By

      3. Tips:

        1. ….|chart count over host by product_name usenull=f useother=f
        2. Only first value after by modifier effect
    2. Timechart

      1. Time is alwarys the X axis
      2. Only first value after by modifier effect
      3. Span=12hr
      4. Use the limit option to include only the 5 best-selling products.
      5. Splunk automatically calculates the top products by totaling each column and taking the top n results (n being the number you specify in your limit).
      6. …|timechart count by product_name limit=0
    3. Iplocation

      1. …|iplocation src_ip
    4. Maps

      1. Marker maps
      2. Choropleth maps
    5. Geostats

      1. …|geostats latfield=xx longfield=xx count
      2. Latfield
    6. Geom

      1. (geom geo_us_states featureIdField=VendorStateProvince)
      2. index=sales sourcetype=vendor_sales VendorID < 3000 |chart count by VendorStateProvince |geom
      3. geo_us_states featureIdField=VendorStateProvince
    7. Trendline

      1. Wma2 weighted moving average
      2. Sma simple moving average
      1. Ema exponenial moving average 指数
    8. Addtotals

      1. Col=true
      2. Label="xx"
      3. Labelfield="xx"
      4. Fieldname=xx
      5. Row=false
    9. Eval

      1. Tostring format values will changing their characteristics
      2. destination field for the eval command
      3. already exists overwritten by the new field
      4. defined in the eval command
    10. Fieldformat

      1. Not change chararistic
    11. Search

      1. index=security sourcetype=linux_secure fail* |stats count by user|search count>3 |sort -count
      2. 不可以接函数,where场景更多
    12. Where

      1. index=network sourcetype=cisco_wsa_squid |stats count by http_content_type |eval type=if(http_content_type LIKE "image%","graphic","other")
      2. No results are found because the search command cannot compare values from two different fields. (As you saw earlier, the where command can do this.)
      3. … | where a>2 AND b>4
    13. Lookup

    14. Transaction

      1. Endwith
      2. Startwith
      3. : The search command must be downstream from the transaction command.
      4. Duration
      5. Eventcount
      6. Maxspan
    15. Name conventions

      1. Group

      2. Type

      3. Platform

      4. Category

      5. Time

      6. Description

      7. Tips:

        1. OPS_WFA_Network_Security_na_IPwhoisAction
        2. It is suggested that you name your Knowledge Objects using 6_ segmented keys.
    16. Field Extractor (FX)

      1. Extract your own field

      2. Access FX via Settings, Fields Sidebar, or Event Action menu

      3. Extraction Methods

        1. Regex
        2. Delimiter
    17. Field Aliaes

      1. A way to normalize data
      2. Support multiple aliases
      3. Applied after field extractions,before lookup
      4. Can apply to lookup
    18. Calculated

      1. A caculated field must be based on an extracted or discovered field, Not from lookup table or search
    19. Tags

      1. Nicknames for related field/values

      2. One or more tags for any field/values

      3. Case Sensitiv

      4. Search syntax

        1. Tag=tagenam
        2. Tag::filed=tagname
        3. Tag=p* (partial field value)
    20. Even Types

      1. Categorizing events based on search
      2. Tagged to group similar types of event
      3. No time range
      4. Can be inclued in a search sting
    21. Macro

      1. Store entire search strings
      2. Time range independent
      3. Pass arguments to the search
      4. Expanding search ctr+shift+e
    22. Workflow

      1. Get workflow
      2. Post workflow
      3. Search workflow
    23. Knowledge Object

    24. Data Models

      1. Data model is structured datasets

      2. 3 types dataset

        1. Events
        2. Searchs
        3. Transacitons
      3. Acceleration

    25. Events Dataset

      1. Constraints
      2. Fields
    26. Dataset field

      1. Auto-extractd

        1. Field type

          1. String
          2. Number
          3. Boolean
          4. IPV4
        2. Field flags

          1. Optional
          2. Required
          3. Hidden
          4. Hidden & required
      2. Eval expression

      3. Lookup

      4. Regular expression

      5. Geo ip

    27. Pivot

      1. Used for creating reports and dashboards, which are based on dataset
    28. CIM Add-on ( Common Information Model)

      1. Normalize data
      2. Easier correlation data
      3. Object permission
    29. Datamodel command

      1. |datamodel Web Web search |fields web*

Splunk笔记的更多相关文章

  1. Splunk 简单笔记

    Splunk Notes source="c:\logs\abc.log" | rex field=url "(?<=\/)(?<ApiId>\w+?) ...

  2. 一起学习 微服务(MicroServices)-笔记

    笔记 微服务特性: 1. 小 专注与做一件事(适合团队就是最好的) 2. 松耦合 独立部署 3. 进程独立 4. 轻量级通信机制 实践: 1. 微服务周边的一系列基础建设 Load Balancing ...

  3. Splunk大数据分析经验分享

    转自:http://www.freebuf.com/articles/database/123006.html Splunk大数据分析经验分享:从入门到夺门而逃 Porsche 2016-12-19 ...

  4. git-简单流程(学习笔记)

    这是阅读廖雪峰的官方网站的笔记,用于自己以后回看 1.进入项目文件夹 初始化一个Git仓库,使用git init命令. 添加文件到Git仓库,分两步: 第一步,使用命令git add <file ...

  5. js学习笔记:webpack基础入门(一)

    之前听说过webpack,今天想正式的接触一下,先跟着webpack的官方用户指南走: 在这里有: 如何安装webpack 如何使用webpack 如何使用loader 如何使用webpack的开发者 ...

  6. SQL Server技术内幕笔记合集

    SQL Server技术内幕笔记合集 发这一篇文章主要是方便大家找到我的笔记入口,方便大家o(∩_∩)o Microsoft SQL Server 6.5 技术内幕 笔记http://www.cnbl ...

  7. PHP-自定义模板-学习笔记

    1.  开始 这几天,看了李炎恢老师的<PHP第二季度视频>中的“章节7:创建TPL自定义模板”,做一个学习笔记,通过绘制架构图.UML类图和思维导图,来对加深理解. 2.  整体架构图 ...

  8. PHP-会员登录与注册例子解析-学习笔记

    1.开始 最近开始学习李炎恢老师的<PHP第二季度视频>中的“章节5:使用OOP注册会员”,做一个学习笔记,通过绘制基本页面流程和UML类图,来对加深理解. 2.基本页面流程 3.通过UM ...

  9. NET Core-学习笔记(三)

    这里将要和大家分享的是学习总结第三篇:首先感慨一下这周跟随netcore官网学习是遇到的一些问题: a.官网的英文版教程使用的部分nuget包和我当时安装的最新包版本不一致,所以没法按照教材上给出的列 ...

随机推荐

  1. ABP框架插件开发

    http://personball.com/abp/2017/08/21/abp-how-to-use-plugin

  2. Vue学习(一):Vue实例

    <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8&quo ...

  3. pandas DataFrame行或列的删除方法

    pandas DataFrame的增删查改总结系列文章: pandas DaFrame的创建方法 pandas DataFrame的查询方法 pandas DataFrame行或列的删除方法 pand ...

  4. SVM知识点

    SVM(Support Vector Machine),支持向量机,有监督学习模型,一种分类模型.在特征空间(输入空间为欧式空间或离散集合,特征空间为欧式空间或希尔伯特空间)中寻找间隔最大化的分离超平 ...

  5. java设计模式之适配器模式以及在java中作用

    适配器作用就是讲一个接口适配到另一个接口,在Java 的I/O类库中有很多这样的需求,如将字符串数据转变成字节数据保存到文件中,将字节数据转变成流数据等. 以InputStreamReader和Out ...

  6. BZOJ 2946 POI2000 公共串 后缀自动机(多串最长公共子串)

    题意概述:给出N个字符串,每个串的长度<=2000(雾...可能是当年的年代太久远机子太差了),问这N个字符串的最长公共子串长度为多少.(N<=5) 抛开数据结构,先想想朴素做法. 设计一 ...

  7. 【集训试题】SiriusRen的卡牌 set

    题意概述: 给出N张卡牌,每张有三个属性a,b,c,同时给出所有属性可能的最大值A,B,C.对于一张卡牌,当这张卡牌至少有两个属性大于另外一张卡牌的对应两个属性的时候,认为这张卡牌更加优秀.现在问有多 ...

  8. HDU 4467 Graph(图论+暴力)(2012 Asia Chengdu Regional Contest)

    Description P. T. Tigris is a student currently studying graph theory. One day, when he was studying ...

  9. phpquery中文手册

    [简介] phpQuery是一个基于PHP的服务端开源项目,它可以让PHP开发人员轻松处理DOM文档内容.更有意思的是,它采用了jQuery的思想,使得可以像使用jQuery一样处理页面内容,获取想要 ...

  10. [剑指Offer] 41.和为S的连续正数序列

    题目描述 小明很喜欢数学,有一天他在做数学作业时,要求计算出9~16的和,他马上就写出了正确答案是100.但是他并不满足于此,他在想究竟有多少种连续的正数序列的和为100(至少包括两个数).没多久,他 ...