Search Under the Hood


Táto časť nie je lokalizovaná

This eLearning course gives students additional insight into how Splunk processes searches. Students will learn about Splunk architecture, how components of a search are broken down and distributed across the pipeline, and how to troubleshoot searches when results are not returning as expected.

certifikovaní lektori

uznávané certifikácie

Široká ponuka technických
a soft skills kurzov

Skvelý zákaznicky

Prispôsobenie kurzov
presne na mieru

Termíny kurzov

Počiatočný dátum: Na vyžiadanie

Forma: E-learning

Dĺžka kurzu: 1 hodina

Jazyk: en

Cena bez DPH: 0 EUR


Forma Dĺžka
Jazyk Cena bez DPH
Na vyžiadanie E-learning 1 hodina en 0 EUR Registrovať
G Garantovaný kurz

Nenašli ste vhodný termín?

Napíšte nám o vypísanie alternatívneho termínu na mieru.


Štruktúra kurzu

Táto časť nie je lokalizovaná

Topic 1 – Investigating Searches

  • Use the Search Job Inspector to examine how a search was processed and troubleshoot performance
  • Use SPL commenting to help identify and isolate problems

Topic 2 – Splunk Architecture

  • Understand the role of search heads, indexers, and forwarders in a Splunk deployment
  • Understand how the components of a bucket (.tsidx and journal.gz files) are used
  • Understand how bloom filters are used to improve search speed

Topic 3 – Streaming and Non-Streaming Commands

  • Describe the parts of a search string
  • Understand the use of centralized vs. distributable commands
  • Create more efficient searches

Topic 4 – Breakers and Segmentation

  • Understand how segmenters are used in Splunk
  • Use lispy to reduce the number of events read from disk

Topic 5 – Commands and Functions for Troubleshooting

  • Using the fieldsummary command
  • Using the makeresults command
  • Using information functions with the eval command
    • the isnull function
    • the typeof function

Predpokladané znalosti

Táto časť nie je lokalizovaná


  • Intro to Splunk eLearning course

Potrebujete poradiť alebo upraviť kurz na mieru?

pruduktová podpora