Splunk doc summary

1.splunk feature

  • indexing


    data source: packaged and custom applications, application servers, web servers, databases, networks, virtual machines, telecoms equipment, operating systems, sensors, and so on.
  • data model


    Data model objects represent different datasets within the larger set of data indexed by splunk enterprise.
  • pivot


    The Pivot Editor lets users map attributes defined by data model objects to a table or chart data visualization without having to write the searches to generate them.Pivots can be saved as reports and added to dashboards.
  • search
  • alerts
  • reports


    Reports are saved searches and pivots.
  • dashboards

2.splunk users

  • Administrator
  • Knowledge Manager
  • Search User
  • Pivot User
  • Developer

3.splunk components

  • Apps
  • Forwarder
  • indexer
  • search head

4.install

Splunk Enterprise installs and runs two windows services, splunkd and splunkweb.New for version 6.2, the splunkd service handles all splunk enterprise operations, and the splunkweb service installs to run only in legacy mode.

To change the Splunk Web service port: 
• Open a command prompt.
• Change to the %SPLUNK_HOME%\bin directory.
• Type in splunk set web-port #### and press Enter.

To change the splunkd port: 
• Open a command prompt, if one isn't already.
• Change to the %SPLUNK_HOME%\bin directory.
• Type in splunk set splunkd-port #### and press Enter.

5.start

D:\Tool\Splunk\bin>splunk.exe start

6.home page

Splunk home includes the splunk enterprise navigation bar, the apps menu, the explore splunk enterprise panel, and a custom default dashboard.

7.get data into splunk enterprise

categorize input sources:

  • Files and directories
  • Network events
  • Windows sources
  • Other sources

ways to speify data inputs:

  • splunk web
  • apps
  • the splunk enterprise cli
  • the inputs.conf configuration file

whers splunk enterprise stores data:


A splunk enterprise data repository is called an index. During indexing, splunk enterprise processes the incoming data stream to enable fast search and analysis, storing the results in the index as events.

  • Rawdata
  • index files

转载于:https://www.cnblogs.com/samrui/p/5037539.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值