Conventions used
There are a number of text conventions used throughout this book.
Code in text
: Indicates code words in text, database table names, folder names, filenames, file extensions, pathnames, dummy URLs, user input, and Twitter handles. Here is an example: “Find the [general]
stanza and replace the serverName
value with forwarder1
.”
A block of code is set as follows:
index=botsv1 earliest=0 index=botsv1 sourcetype=iis http_referer=* index=botsv1 earliest=0 sourcetype=suricata | eval bytes=bytes_in+bytes_out index=botsv1 earliest=0 sourcetype=iis referer_domain=* | table _time, cs_Referer, referer_domain index=botsv1 earliest=0 sourcetype="WinEventLog:Security" | stats count by Account_Name
When we wish to draw your attention to a particular part of a code block, the relevant lines or items are set in bold:
index=botsv1 earliest=0 sourcetype=iis c_ip="23.22.63.114" OR c_ip="52.23.25.56" | <transforming commands> | search...
Any command-line input or output is written as follows:
/opt/splunk/bin/splunk set servername indexer /opt/splunk/bin/splunk set default-hostname indexer /opt/splunk/bin/splunk restart
Bold: Indicates a new term, an important word, or words that you see onscreen. For instance, words in menus or dialog boxes appear in bold. Here is an example: “Click on the orange Confirm Changes button to continue.”
Tips or important notes
Appear like this.