This chapter provided an introduction to the most common knowledge objects Splunk users can leverage to enhance their data. We learned how to extract and create new fields in events, how to group and/or replace search criteria with event types and macros, how to tag and categorize event fields with tags and aliases, and how to enhance the data in event fields with lookups. Then, we looked at creating datasets and data models to be used in pivot tables so our less technical users can leverage the power of the data provided by Splunk in their reports and dashboards. In the next chapter, we'll cover how to create reports, dashboards, and alerts – see you there!
United States
Great Britain
India
Germany
France
Canada
Russia
Spain
Brazil
Australia
Singapore
Hungary
Ukraine
Luxembourg
Estonia
Lithuania
South Korea
Turkey
Switzerland
Colombia
Taiwan
Chile
Norway
Ecuador
Indonesia
New Zealand
Cyprus
Denmark
Finland
Poland
Malta
Czechia
Austria
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Netherlands
Bulgaria
Latvia
South Africa
Malaysia
Japan
Slovakia
Philippines
Mexico
Thailand