A Hands-On Guide to Splunk Enterprise Security

所在平台: Udemy

课程主页: https://www.udemy.com/course/a-hands-on-guide-to-splunk-enterprise-security/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Splunk企业安全实践指南 课程概述:本课程将带领您深入了解Splunk的用户界面(UI),并能够独立导航UI的各项功能。您将学习如何操作Splunk主页、Splunk工具栏、Splunk网页,如何将数据导入Splunk,指定数据输入的位置,了解Splunk存储数据的方式,以及如何将教程数据导入Splunk。课程中还包括使用Splunk搜索、搜索操作和模式、搜索结果工具、事件、字段及其提取等内容。您将掌握运行更精准的搜索、使用搜索语言及搜索助手的技能。 此外,您还将开始使用Splunk的基本转换命令,创建报告和仪表板,学习如何保存和共享报告,并能够创建警报。 课程将介绍Splunk的工作原理,包括数据管道的各个阶段。Splunk是一个分布式系统,用于摄取、处理和索引日志数据。其处理数据的三个阶段包括: 1. 数据输入:Splunk从源头摄取原始数据流,将其拆分为64K块,并添加元数据键,如主机名、来源、字符编码及数据应存储的索引。 2. 数据存储:Splunk解析日志数据,通过分解行、识别时间戳,创建独立事件并用元数据键进行注释,最后根据操作人员定义的转换规则对事件数据进行转换,并将解析后的事件写入磁盘。 3. 数据搜索:此阶段用户可以查询、查看并使用事件数据。根据用户的报告需求,Splunk创建报告、仪表板和警报等对象。 课程还将提供关于企业Splunk安全的实践视频(ES1、ES2、ES3和ES4),帮助您掌握Splunk的应用。

课程评论(0条)

课程详情

You will understand Splunk's user interface -UI. You will be able to navigate UI features on your own: Navigating Splunk web: Splunk home, Splunk bar, Splunk web, getting date into Splunk, how to specify data inputs, where Splunk stores data, getting tutorial data into Splunk, using Splunk search, search actions, and modes, search results tools, events, what are fields, extracted fields, find and select fields, run more targeted searches, use the search language, learn with search assistant.You can start using the Splunk's basic transforming commands, can create reports and dashboards, you will know how to save and share reports and also can create alerts after completing these sections.How Splunk Works: Stages in the Data PipelineSplunk is a distributed system that ingests, processes and indexes log data. Splunk processes data in three stages:Data Input - Splunk ingests the raw data stream from the source, breaks it into 64K blocks, and adds metadata keys, including hostname, source, character encoding, and the index the data should be stored in.Data Storage - Splunk parses log data, by breaking it into lines, identifying timestamps, creating individual events and annotating them with metadata keys. It then transforms event data using transformation rules defined by the operator. Finally, Splunk writes the parsed events to disk, pointing to them from an index file which enables fast search across huge data volumes.Data Search - at this stage Splunk enables users to query, view and use the event data. Based on the user's reporting needs, it creates objects like reports, dashboards and alerts.Hands-on practical videos on Enterprise Splunk Security: ES1, ES2, ES3 & ES4 will help you master Splunk!

课程标签

0人关注该课程

主题相关的课程