|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/splunk-search-and-reporting/
课程评论:没有评论
**课程名称:** Splunk 搜索与报告 **课程概述:** 本课程旨在教授 Splunk 的基础搜索和报告功能,帮助您快速上手,并深入理解字段(fields)的概念。通过学习最佳实践,您将能够创建更复杂的搜索查询。 Splunk Enterprise 默认提供的“搜索与报告”应用是与数据交互、创建报告、警报和仪表盘(Dashboard)的核心界面。该应用在您登录 Splunk Web 时展示,是您进入 Splunk 世界的入口。 Splunk 的核心能力之一是日志处理。它能够存储海量的日志数据,并提供类似 Google 搜索引擎般快速的数据检索能力,适用于各种设备产生的日志文件。 Splunk 的搜索处理语言(SPL)是一个极其强大的工具,能够从海量数据中提取有价值的信息,并在特定上下文中进行相关的统计分析。 Splunk 可以索引任何可表示为文本的机器数据,无需预先定义表和字段。Splunk 没有固定的模式(schema),而是在搜索时进行字段提取,这赋予了极大的灵活性。它不会因容量限制而牺牲数据粒度,能够无缝索引每天数百 TB 的数据,并存储几乎无限量的数据。 Splunk 仪表盘允许您同时监控所有系统。当问题发生时,您可以立即着手解决,甚至在问题真正影响系统之前就开始预警。更重要的是,仪表盘能够清晰地展示潜在问题的迹象,帮助您进行预防性维护。
This course is intended to explain the basics of search and reporting. This will help you start with search and reporting.Also help you do understand the basics about the fields. You can create complex search queries by following the best practise.By default, Splunk Enterprise provides the Search and Reporting app. This interface provides the core functionality of Splunk Enterprise. The Splunk Home page provides a view to the app when you first log into Splunk Web.It has default app as search and reporting by which you interact with the data, and create reports, alerts, Dashboard etc.Log processing is one of the core competencies of Splunk. It stores all your logs and provides very fast search capabilities roughly in the same way Google does for the internet device log files.The Search Processing Language (SPL) for Splunk is an extremely powerful tool for extracting meaning out of vast amounts of data and performing statistical operations on what is relevant in a specific context.Splunk indexes any kind of machine data that can be represented as text and there is no need to define tables and fields before you can store data. Splunk does not have a fixed schema. In fact, it performs field extraction at search time. This aspect allows for great flexibility.It does not reduce the granularity of older events, compressing many data points into one because of capacity limits. It can seamlessly index hundreds of terabytes per day and keep practically unlimited amounts of data.Splunk dashboards allow you to monitor all of your systems at once, so when a problem occurs you can start looking for a solution even before the problem starts bothering the system, or even better, its dashboard allows to clearly look for signs of a possibly arising problem.