EQALIS APPSTORE

 

EQALIS Symantec Virus Log App

Allows users of Symantec Anti-Virus 2009 software to use Splunk to index, search and report on its logs.

 

View

BLOG

 

May 3rd, 2013

Splunk buzz at Infosec 2013

The buzz around Splunk was heightened by the presentation of the Best Enterprise Security Solution Award by SC Magazine at the SC Magazine Awards Europe on the opening evening.

 

View

PRODUCT TRIALS

 

Splunk & PCI Compliance - Whitepaper

A Whitepaper describing how to map Splunk Enterprise to support your PCI requirements.

 

View

Call Us - 0845 643 9180

Searching and Reporting with Splunk 5.0

 

This nine-hour follow-on to the Using Splunk class focuses on Splunk's search and reporting commands. Scenario-based examples and hands-on challenges enable users to create robust searches, reports and charts. Major topics include statistics and reporting, formatting and calculating results, charting commands and options, correlating events, summary indexing, enriching data with lookups, and more.

 

Course Topics

  • Getting Statistics

  • Analyzing, Calculating, and Formatting

  • Creating Charts

  • Correlating Events

  • Enriching Data with Lookups

  • Summary Indexing

  • Creating and Using Macros

 

Class Format

Instructor-led lecture with labs. Delivered via virtual classroom or at your site. 

 

Prerequisites

Using Splunk

 

Course Objectives

 

Lesson 1 - Search Fundamentals

  • Examine the anatomy of a search

  • Understand search language syntax concepts

  • Review fields and use the fields command

  • Create a table• Examine multi-value fields

 

Lesson 2 - Getting Statistics

  • Understand the stats command

  • Display top and rare values for given fields

  • Use the stats command to create statistical reports

 

Lesson 3 - Formatting and Calculating

  • Understand the eval command

  • Perform calculations on field values

  • Convert, round, and format field values

  • Use conditional statements

 

Lesson 4 - Charting 

  • Create charts and time charts

  • Split values into multiple series

  • Omit null and other values from charts

  • Apply statistical functions

 

Lesson 5 - Correlating Events

  • Identify transactions

  • Correlate events

  • Report on transactions

 

Lesson 6 - Enrich Data with Lookups

  • Create a lookup table

  • Define a lookup

  • Configure automatic and time-based lookups

 

Lesson 7 - Summary Indexing

  • Define summary indexing

  • Populate and run searches against a summary index

  • Identify and correct gaps and overlaps in a summary index

 

Lesson 8 - Macros

  • Manage macros

  • Create and use a basic macro

  • Define and use arguments and variables for a macro

 

Find Out More


 
22.04.2013

Using Splunk

Go »

22.04.2013

Searching and Reporting with Splunk 5.0

Go »

24.04.2013

Advanced Splunk Administration

Advanced Splunk Administration

Go »

29.04.2013

Architecting and Deploying Splunk 5.0

Architecting and deploying Splunk 5.0

Go »

01.05.2013

Developing Apps with Splunk

Developing Apps with Splunk

Go »

View All
 
Videos

VIDEOS

Selection of videos from our youtube channel
Blog

BLOG

EQALIS has gained its edge by continually seeking out new life in the IT management, IT compliance and IT security product fields to help organisations challenge their current approaches.
Product Trials

PRODUCT TRIALS

Splunk & PCI Compliance - Whitepaper
A Whitepaper describing how to map Splunk Enterprise to support your PCI requirements.
View All