Documente Academic
Documente Profesional
Documente Cultură
Workshops
Getting Started User
Training
Name
Title
Date
Agenda
Copyright
Platforms
Max (OS10)
Storage 12-48% of raw data size.
Browsers
Copyright
Where to download
Software download
Documentation
http://www.splunk.com
http://www.splunk.com/base/Documentation
Whitepapers
Copyright
http://www.splunk.com/page/securelink/download/Splunk_Produc
t_Datasheet/
Install Splunk
www.splunk.com/down
load
32
or 64 bit?
Indexer
or Universal
Start Splunk
Forwarder?
WIN: \Program Files\Splunk\bin\splunk.exe start
Other: /opt/splunk/bin/splunk start
Splunk Home
WIN:
\Program Files\Splunk
Other:
Copyright
/opt/splunk (Applications/splunk)
Splunk Licenses
Free Download Limits Indexing to 500MB/day
Enterprise Trial License expires after 60 days
Reverts to Free License
Copyright
Add data
Getting Started App
Install an App (Splunk for Windows, *NIX)
Copyright
Search is an App
Copyright
Searching
Search > *
Select Time Range
Historical, custom, or real-time
Using the timeline
Click events and zoom in and out
Click and drag over events for a specific range
Copyright
10
Searching cont.
11
Search Assistant
Contextual Help
advanced typeahead
History
search
commands
Search Reference
short/long description
examples
Copyright
12
Deployment and
Integration
14
syslog
TCP/UD
P
Mounted File
Systems
\\hostname\mount
WMI
Event Logs
Performance
Copyright
Active
Directo
ry
shell scripts
custom parsers
cod batch loading
shel
l
perf
Event Logs
performance counters
registry monitoring
Active Directory
monitoring
virtual
host
Windows hosts
Agent-less Data
Input
Scripted
Inputs
Windows Inputs
Splunk Forwarder
15
Windows
hosts
Parsing
parsing pipeline actually consists of three pipelines:
parsing,
merging, and
typing,
which together handle the parsing function
Copyright
16
parsing
Extracting default fields for each event, - host,
source, and sourcetype.
character set encoding.
Identifying line termination using linebreaking rules.
Identifying timestamps or creating them if they don't
exist.
mask sensitive event data
configured to apply custom metadata to incoming
events.
Copyright
17
Indexing
Breaking all events into segments that can then be
searched upon.
Building the index data structures.
Writing the raw data and index files to disk, where
post-indexing compression occurs
Copyright
18
Indexing
Preconfigured indexes, including:
main: This is the default Splunk Enterprise index. All
processed data is stored here unless otherwise
specified.
_internal: Stores Splunk Enterprise internal logs and
processing metrics.
_audit: Contains events related to the file system
change monitor, auditing, and all user search history.
Copyright
19
Copyright
20
performance.
Universal Regular
Universal Forwarder
Forwarde (Heavy)
Deployment
r
Forwarder
Logs
Messag
Configurations
Metrics
es
Routing,
Filtering,
Cloning
Splunk
Web
Python
Libraries
Event
Based
Routing
Scripted
Inputs
Copyright
Scripts
21
Search
A search peer is an indexer that services requests from
search heads in a distributed search deployment.
Search peers are also sometimes referred to as indexer nodes.
A search head is a Splunk instance configured to distribute
searches to indexers, or search peers.
Search heads can be either dedicated or not, depending on
whether they also perform indexing.
Dedicated search heads don't have any indexes of their own
(other than the usual internal indexes). Instead, they consolidate
results that originate from remote search peers.
Copyright
22
Functions at a glance
Functions
Indexer
Indexing
Web
Direct search
Forward to
indexer
Deploy
configurations
Copyright
Search head
Forwarder
Deployment
server
x
x
x
x
x
23
Horizontal Scaling
Load balanced search and indexing for massive, linear
scale out.
Distributed
Search
Forwarder
Auto Load
Balancing
Copyright
24
Multiple Datacenters
Distributed
Search
London
Copyright
Hong Kong
Tokyo
25
New York
Data Redundancy
Clone data to multiple index servers to eliminate a single point of
failure.
Active
Hot Standby
Forwarding to DR site
Data
Cloning
Copyright
26
High Availability
Distributed
Search
Clone Group 2 : Complete
Dataset
27
Copyright
28
Watch
Lists
CMDB
CRM/E
RP
Copyright
29
Problem Investigation
Problem Investigation
Share
Search Save
es
Searche
Problem
Investigation
s
Manage
Users
NOT
tag=PCI
App=ER
P
Map LDAP & AD groups to flexible Splunk roles. Define any search as a filter.
Copyright
30
Problem Investigation
Copyright
31
Deployment Monitoring
Keep Tabs On Your Splunk Enterprise Deployment
Licenses
Copyright
Sourcetypes
Indexers
32
Forwarders
Listen to your data.
Scalability Use
CASE
Copyright
Copyright
Splunk
one)
(all in
Users
Copyright
RULE
#1
2011,
Splunk
Inc.
Spunk
Indexer
Splunk Search
Head
Users
Copyright
Spunk
Indexer
Spunk
Indexer
Splunk Search
Head
Users
Copyright
Spunk
Indexer
Spunk
Indexer
(n) Indexers
Splunk Search
Head
Users
Copyright
Spunk
Indexer
1 Commodity Server
Spunk
Indexer
Spunk
Indexer
Splunk Search
Head
(n) Indexers
Load Bal.
Spunk
Indexer
Splunk Search
Head
Users
Copyright
Spunk
Indexer
Spunk
Indexer
Splunk Search
Head
Splunk Search
Head
Use Case
trouble shooting and
summary reporting
8+ Index Server,
Load Bal. 1 Search Server
Spunk
Indexer
Spunk
Indexer
(n) Indexers
Tier 1
SAN
Splunk Search
Head
Spunk
Indexer
Splunk Search
Head
Load Bal.
Users
Copyright
Multi-datacenter or deployment
If you have multiple data centers, it is often best to leave the data local
and use distributed search between two deployments.
If you have data that naturally partitions such that users would rarely
search across the data, partitioning entire deployments can help.
Obviously for DR as well.
Copyright
Copyright
Community-driven
knowledge
exchange and Q&A
answers.splunk.com
47
http://www.splunk.com/base/Documentation
Technical Support
http://www.splunk.com/support
Videos
http://www.splunk.com/videos
Education
http://www.splunk.com/goto/education
Professional Services
Copyright
48