To build on the strong foundation of the Splunk skills attained using this book so far, we want to introduce you to a few extra skills that will help make you a powerful Splunker. Throughout the book, you have gained the essential skills required to use Splunk effectively. In this chapter, we will look at some best practices you can incorporate into your Splunk instance:
- Indexes for testing
- Searching within an index
- Searching within a limited time frame
- How to do quick searches via fast mode
- How to use event sampling
- Using the fields command to improve performance
We will also provide some advanced searches that you can use as templates when the need arises. These include:
- Doing a subsearch, or a search within a search
- Using append and join
- Using eval with if
- Using eval with match
Tip from the Fez: Throughout this book, we have seen how...