What this book covers
Chapter 1, Introduction to Splunk and its Core Components, is a discussion on the increase in Big data and how tools such as Splunk make it easier to deal with this data. The chapter discusses the basic Splunk components, such as indexers and search heads, and introduces the BOTS dataset, which will be used to learn Splunk SPL.
Chapter 2, Setting Up the Splunk Environment, provides step-by-step instructions on setting up Splunk components. It also includes an introduction to access management.
Chapter 3, Onboarding and Normalizing Data, provides step-by-step instructions on onboarding data into Splunk.
Chapter 4, Introduction to SPL, provides an introduction to the Splunk SPL, including different Splunk commands.
Chapter 5, Reporting Commands, Lookups, and Macros, is a continuation of the introduction to the Splunk SPL, including more advanced commands, lookups, and macros.
Chapter 6, Creating Tables and Charts Using SPL, provides step-by-step instructions on creating different visualizations in Splunk.
Chapter 7, Creating Dynamic Dashboards, builds on previous chapters and incorporates tables, charts, and other visualizations into dashboards.
Chapter 8, Licensing, Indexing, and Buckets, is an introduction to Splunk licensing and indexing. The discussion includes information about Splunk queues and pipelines.
Chapter 9, Clustering and Advanced Administration, is a discussion of Splunk indexer and search head clustering.
Chapter 10, Data Models, Acceleration, and Other Ways to Improve Performance, is an introduction to data models and how they improve search performance.
Chapter 11, Multisite Splunk Deployments and Federated Search, is an exploration of different Splunk deployments and concepts, including multisite deployments, hybrid search, and federated search.
Chapter 12, Container Management, is an introduction to the concept of container management, including Docker and Kubernetes. It includes an introduction to the Splunk add-ons and apps developed for getting container data into Splunk.