Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
We Got Splunk
Its Installed
Cool
Now What?
Who Am I?
5i) #ata
(ots of 6sers
(ots of #atat"pes
+i)hl" #istri7ute%
Splunk PS Work
*a8or A$ti0ities
App Inte)ration
App #e0elopment
-nhan$ements
/epairs
Ar$hite$ture
*i)rations
*er)in)/5reakout
6p)ra%es
#//+A
*ore transparen$"
5ut Isn:t Splunk -;?
*ore transparen$"
Note@ P? B Pro?ip C ?hese are keepers
Content A0aila7le NowD
?alk@ aplura<$om/splunkli0e%$
5P@ aplura<$om/splunk7p
Si9in) Your #eplo"ment
3e" -lements
A%ministration
/eferen$e Ar$hite$ture in H5 *in
#eplo"ment Ser0er
E#SF@
*ana)es All
Splunk Confi)s
0ia Apps
Platform
In%epen%ent
-nsures
6niformit"
S"slo) /e$eipt
'ile *onitor
#5 *onitor
S$ript -=e$ution
Consi%er@
/elia7ilit"
*ana)ement
-n$r"ption
Parsin) ,perations@
?imestampin)
-0ent 5reakin)
In%e=e% 'iel%s
I+'@
#eplo" !B . for +A
Consi%er /e)ional
or ;onespe$ifi$
Splunk In%e=ers@
I+' ?asks
Write #ata
/etrie0e #ata
Plan as a #5
/e4uire 211& I,PS
G*s are tri$k"
Sear$h +ea% is
where the ma)i$
happens
?he S+ 4ueries the
In%e=ers
A$$ounts,
Permissions,
#ash7oar%s,
Sear$hes, an%
'iel%s, all li0e in
Sear$h
*i)rations, *i)rations, *i)rationsD
*i)rations, *i)rations, *i)rationsD
?his is m" fa0orite part of EIw&F
JWarnin)J
When in %ou7t@
/ea% #o$s
+it Splunk7ase
Call Support
Call PS
Prep Yourself
Steps@
/inse, repeat<
*i)rate S.#@ Separate Parsin)
Now 6'!I+'!Solo1
*i)rate S.#@ #ist Sear$h
No lo$al in%e=in)
/ea%" to *i)rate@
Start %ataflow
*er)e In%e= /ename S$ript
I use (arr" Wall:s VrenameV perl s$ript E$omes with 67untu 7ut N,? Cent,S//+-(F
(arr" Wall:s VrenameV takes se%st"le mat$hes, so the followin) will work@
/7in/sh
$% OSP(6N3M#5/'A(G)'IN*)+/E%7W$ol%%7F
S?A/?B111
for i in ls rt% %7MJX %o S?A/?BOEEOS?A/? & 1FFX rename n0 Vs/%&O/OS?A/?/V Oi X%one
?he ls with rt% ar)s, sorts re0erse 7" time an% onl" shows the %ire$tories, so the ol%est 7u$ket
will 7e liste% first an% therefore will 7e the first 7u$ket in "our list to keep the or%er somewhat
the wa" it woul% ha0e 7een ori)inall"<
?he 7usiness with the S?A/? thin) helps to maintain a $ounter so "ou $an mo0e throu)h
them one at a time< ?his is important when "ou are %oin) 7oth the +,? then C,(# #5s, an%
therefore "ou nee% to start on a spe$ifi$ num7er<
(i$ense *aster *i)ration
S$ripte% Input
If hea0"/fast, ha0e same s$ript lo) to file then Splunk monitor that file
S"slo)
#/ is not intuiti0e
No e0ent repli$ation
In$reases Performan$e
-=$eption
'rin)e $ase
We ha0e a lot of %ata< ?oo mu$h?
.S11J.k7s B .S11k7s
>enerall", no<
6sera)ents are
%iffi$ult
Parsin) them is a
ni)htmare
Cate)or" information
for more than Q<5
million %omains
We7 Pro=ies
#NS
Content A0aila7le NowD
?alk@ www<aplura<$om/splunkli0e%$
5P@ www<aplura<$om/splunk7p