Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Splunk Best Practices
Splunk Best Practices

Splunk Best Practices: Operational intelligent made simpler

eBook
AU$47.99 AU$53.99
Paperback
AU$67.99
Subscription
Free Trial
Renews at AU$24.99p/m

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Billing Address

Table of content icon View table of contents Preview book icon Preview Book

Splunk Best Practices

Chapter 2. Data Inputs

In Splunk there are many ways to get data into the indexers, which make for the ability to be very creative in doing so. Between the apps that are provided on Splunk base and the other methods that can be developed by an individual, it paves the way to be very dynamic in getting data in to get value out of your data.

In this chapter I'm going to assume that you have your Forwarders installed.

Let's start with most of the agents and applications to get data into Splunk.

Agents

These are the thin and thick clients from Splunk that can be used to forward data to Splunk.

Splunk Universal Forwarder

Splunk Universal Forwarder is a light agent that is installed on a device that enables you with quite a bit of functionality to get data into a Splunk index. The name is pretty self-explanatory, as this agent is designed to simply forward data to a Splunk index. This is often the most common method to get data into Splunk.

Splunk Heavy Forwarder

This is a heavy agent. It is basically a full version of Splunk that is installed on a device in order to perform the same data-forwarding functionality as the Universal Forwarder, with the added benefit of being able to perform some more complex functions.

It is often used as a centralized point for data gathering of multiple systems, as well as a data router to collect, route, and scrub data appropriately before it hits an indexer. These are usually standalone machines within your Splunk infrastructure.

Search Head...

Data inputs

Knowing all of the applications and methods we can use to get data into Splunk, let's talk about the types of data inputs from data sources, and how they get to the indexer. There are six general types of data inputs in Splunk:

  • API inputs
  • Database inputs
  • Monitoring inputs
  • Scripted inputs
  • Modular inputs
  • Windows inputs

API inputs

There are two ways to get REST API data into Splunk:

  • Download the REST API modular input, and install it into your Heavy Forwarder
  • Write a REST API poller using cURL or some other method to query the API, and scrub the output for the data you need

If at all possible, use the REST API modular input from Splunk, as it is very easy to set up and use. Just figure out your URL, and set up the API input and it's interval that you want it to be polled at.

Tip

Q: When would you ever use a custom API input if Splunk already has a REST API input available? A: When one doesn't already exist, and it's the only way to get data from your system.

An example of...

Deployment server

Now that we know what types of data inputs there are, let's say that you have 500 Forwarders and they are different parts of unique systems. How do you manage all of that?

I've got three words for you: Splunk deployment server.

If you're not familiar with Splunk deployment server, I highly recommend you become familiar. With a large deployment of Splunk it's surely the easiest way to manage all of your data inputs for your various systems:

  • Basics: As a general rule of thumb, in Splunk best practices, in Splunk architecture, there should be at least one deployment server. That deployment server would sit behind a load balancing device (let's use F5) and have its own DNS address.
  • Reason: Because if anything ever happens to your DS, and it has a catastrophic failure, what happens when you need to spin up a new one and you can't have the same IP address? Assuming that you don't have a system such as Puppet, Chef, or StackIQ to use to manage your...

Summary

In this chapter, we have discussed how to move on to understanding what kinds of data inputs Splunk uses in order to get data inputs. We have seen how to enable Splunk to use the methods which they have developed in data inputs. Finally, we have gained brief knowledge about the data inputs for Splunk.

In the next chapter, we will learn about how to format all incoming data to a Splunk-friendly format, pre-indexing, in order to ease search querying and knowledge management going forward.

Left arrow icon Right arrow icon
Download code icon Download Code

Key benefits

  • This is the most up-to-date guide on the market and will help you finish your tasks faster, easier, and more efficiently.
  • Highly practical guide that addresses common and not-so-common pain points in Splunk.
  • Want to explore shortcuts to perform tasks more efficiently with Splunk? This is the book for you!

Description

This book will give you an edge over others through insights that will help you in day-to-day instances. When you're working with data from various sources in Splunk and performing analysis on this data, it can be a bit tricky. With this book, you will learn the best practices of working with Splunk. You'll learn about tools and techniques that will ease your life with Splunk, and will ultimately save you time. In some cases, it will adjust your thinking of what Splunk is, and what it can and cannot do. To start with, you'll get to know the best practices to get data into Splunk, analyze data, and package apps for distribution. Next, you'll discover the best practices in logging, operations, knowledge management, searching, and reporting. To finish off, we will teach you how to troubleshoot Splunk searches, as well as deployment, testing, and development with Splunk.

Who is this book for?

This book is for administrators, developers, and search ninjas who have been using Splunk for some time. A comprehensive coverage makes this book great for Splunk veterans and newbies alike.

What you will learn

  • Use Splunk effectively to gather, analyze, and report on operational data throughout your environment
  • Expedite your reporting, and be empowered to present data in a meaningful way
  • Create robust searches, reports, and charts using Splunk
  • Modularize your programs for better reusability.
  • Build your own Splunk apps and learn why they are important
  • Learn how to integrate with enterprise systems
  • Summarize data for longer term trending, reporting, and analysis

Product Details

Country selected
Publication date, Length, Edition, Language, ISBN-13
Publication date : Sep 21, 2016
Length: 244 pages
Edition : 1st
Language : English
ISBN-13 : 9781785289415
Vendor :
Splunk
Category :
Tools :

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Billing Address

Product Details

Publication date : Sep 21, 2016
Length: 244 pages
Edition : 1st
Language : English
ISBN-13 : 9781785289415
Vendor :
Splunk
Category :
Tools :

Packt Subscriptions

See our plans and pricing
Modal Close icon
AU$24.99 billed monthly
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Simple pricing, no contract
AU$249.99 billed annually
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just AU$5 each
Feature tick icon Exclusive print discounts
AU$349.99 billed in 18 months
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just AU$5 each
Feature tick icon Exclusive print discounts

Frequently bought together


Stars icon
Total AU$ 204.97
Splunk Best Practices
AU$67.99
Advanced Splunk
AU$75.99
Splunk Essentials
AU$60.99
Total AU$ 204.97 Stars icon

Table of Contents

10 Chapters
1. Application Logging Chevron down icon Chevron up icon
2. Data Inputs Chevron down icon Chevron up icon
3. Data Scrubbing Chevron down icon Chevron up icon
4. Knowledge Management Chevron down icon Chevron up icon
5. Alerting Chevron down icon Chevron up icon
6. Searching and Reporting Chevron down icon Chevron up icon
7. Form-Based Dashboards Chevron down icon Chevron up icon
8. Search Optimization Chevron down icon Chevron up icon
9. App Creation and Consolidation Chevron down icon Chevron up icon
10. Advanced Data Routing Chevron down icon Chevron up icon

Customer reviews

Rating distribution
Full star icon Full star icon Full star icon Full star icon Half star icon 4.8
(5 Ratings)
5 star 80%
4 star 20%
3 star 0%
2 star 0%
1 star 0%
olu babacamp Jun 19, 2017
Full star icon Full star icon Full star icon Full star icon Full star icon 5
it came intact in intact.The love the detail and well explained material.
Amazon Verified review Amazon
Nicolas Giordano Oct 16, 2019
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Excellent. Highly recommendable.
Amazon Verified review Amazon
Katie Oct 23, 2019
Full star icon Full star icon Full star icon Full star icon Full star icon 5
I absolutely loved the content in this book. 10/10. Would recommend. The author is super hot too. Must read!!!!
Amazon Verified review Amazon
Gerald Partsch Jun 30, 2017
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Valuable information for the Splunk administrator
Amazon Verified review Amazon
Lady Nwig Nov 27, 2022
Full star icon Full star icon Full star icon Full star icon Empty star icon 4
The context overall is more for someone that has been doing this a while and would like to enhance their best practices on the job. I was looking for a more of a beginner guide for best practices.
Amazon Verified review Amazon
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

How do I buy and download an eBook? Chevron down icon Chevron up icon

Where there is an eBook version of a title available, you can buy it from the book details for that title. Add either the standalone eBook or the eBook and print book bundle to your shopping cart. Your eBook will show in your cart as a product on its own. After completing checkout and payment in the normal way, you will receive your receipt on the screen containing a link to a personalised PDF download file. This link will remain active for 30 days. You can download backup copies of the file by logging in to your account at any time.

If you already have Adobe reader installed, then clicking on the link will download and open the PDF file directly. If you don't, then save the PDF file on your machine and download the Reader to view it.

Please Note: Packt eBooks are non-returnable and non-refundable.

Packt eBook and Licensing When you buy an eBook from Packt Publishing, completing your purchase means you accept the terms of our licence agreement. Please read the full text of the agreement. In it we have tried to balance the need for the ebook to be usable for you the reader with our needs to protect the rights of us as Publishers and of our authors. In summary, the agreement says:

  • You may make copies of your eBook for your own use onto any machine
  • You may not pass copies of the eBook on to anyone else
How can I make a purchase on your website? Chevron down icon Chevron up icon

If you want to purchase a video course, eBook or Bundle (Print+eBook) please follow below steps:

  1. Register on our website using your email address and the password.
  2. Search for the title by name or ISBN using the search option.
  3. Select the title you want to purchase.
  4. Choose the format you wish to purchase the title in; if you order the Print Book, you get a free eBook copy of the same title. 
  5. Proceed with the checkout process (payment to be made using Credit Card, Debit Cart, or PayPal)
Where can I access support around an eBook? Chevron down icon Chevron up icon
  • If you experience a problem with using or installing Adobe Reader, the contact Adobe directly.
  • To view the errata for the book, see www.packtpub.com/support and view the pages for the title you have.
  • To view your account details or to download a new copy of the book go to www.packtpub.com/account
  • To contact us directly if a problem is not resolved, use www.packtpub.com/contact-us
What eBook formats do Packt support? Chevron down icon Chevron up icon

Our eBooks are currently available in a variety of formats such as PDF and ePubs. In the future, this may well change with trends and development in technology, but please note that our PDFs are not Adobe eBook Reader format, which has greater restrictions on security.

You will need to use Adobe Reader v9 or later in order to read Packt's PDF eBooks.

What are the benefits of eBooks? Chevron down icon Chevron up icon
  • You can get the information you need immediately
  • You can easily take them with you on a laptop
  • You can download them an unlimited number of times
  • You can print them out
  • They are copy-paste enabled
  • They are searchable
  • There is no password protection
  • They are lower price than print
  • They save resources and space
What is an eBook? Chevron down icon Chevron up icon

Packt eBooks are a complete electronic version of the print edition, available in PDF and ePub formats. Every piece of content down to the page numbering is the same. Because we save the costs of printing and shipping the book to you, we are able to offer eBooks at a lower cost than print editions.

When you have purchased an eBook, simply login to your account and click on the link in Your Download Area. We recommend you saving the file to your hard drive before opening it.

For optimal viewing of our eBooks, we recommend you download and install the free Adobe Reader version 9.