In many of the previous chapters, we leveraged Splunk's Search Processing Language (SPL) quite a bit to build searches, reports, and dashboards. In this chapter, we will learn about datasets and will focus on leveraging Splunk's Data Model and Pivot functionality. We will demonstrate how datasets can be leveraged by less technical users to easily build reports, charts, and dashboards.
A dataset in Splunk is best described as a collection of user-defined data that can be leveraged for a specific purpose. Datasets can be viewed and managed from the Datasets Listing page, available from the default menu bar in any Splunk application. There are currently three types of dataset in Splunk:
- Lookup Datasets
- Table Datasets
- Data Model Datasets
These three types of dataset can be visualized using Splunk's Pivot tool and allow users to create dynamic reports...