This chapter provided an introduction to the most common knowledge objects Splunk users can leverage to enhance their data. We learned how to extract and create new fields in events, how to group and/or replace search criteria with event types and macros, how to tag and categorize event fields with tags and aliases, and how to enhance the data in event fields with lookups. Then, we looked at creating datasets and data models to be used in pivot tables so our less technical users can leverage the power of the data provided by Splunk in their reports and dashboards. In the next chapter, we'll cover how to create reports, dashboards, and alerts – see you there!
United States
United Kingdom
India
Germany
France
Canada
Russia
Spain
Brazil
Australia
Argentina
Austria
Belgium
Bulgaria
Chile
Colombia
Cyprus
Czechia
Denmark
Ecuador
Egypt
Estonia
Finland
Greece
Hungary
Indonesia
Ireland
Italy
Japan
Latvia
Lithuania
Luxembourg
Malaysia
Malta
Mexico
Netherlands
New Zealand
Norway
Philippines
Poland
Portugal
Romania
Singapore
Slovakia
Slovenia
South Africa
South Korea
Sweden
Switzerland
Taiwan
Thailand
Turkey
Ukraine