Chapter 4. Knowledge Management
In this chapter we are going to learn some techniques to manage incoming data in your Splunk indexers, some basics on how to leverage those knowledge objects to enhance performance when searching, as well as the pros and cons of pre- and post-field extraction.
Now that we've learned how to get all of our data into Splunk in effective ways, the next question is How can I search for what I want? That is a loaded question with Splunk, because any ninja out there will answer that with the question, What do you want to see?
Understanding the basics of the search syntax, as well as search behavior, is a great way of understanding why you need to create events, fields, and lookups. Have you ever been to a Splunk event, seen people just clicking away at dashboards and noticed how smoothly it operates? That's because for weeks prior to an event people are behind the scenes building knowledge objects to make everything flow smoothly during a presentation...