Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Splunk 9.x Enterprise Certified Admin Guide

You're reading from  Splunk 9.x Enterprise Certified Admin Guide

Product type Book
Published in Aug 2023
Publisher Packt
ISBN-13 9781803230238
Pages 256 pages
Edition 1st Edition
Languages
Author (1):
Srikanth Yarlagadda Srikanth Yarlagadda
Profile icon Srikanth Yarlagadda

Table of Contents (17) Chapters

Preface Part 1: Splunk System Administration
Chapter 1: Getting Started with the Splunk Enterprise Certified Admin Exam Chapter 2: Splunk License Management Chapter 3: Users, Roles, and Authentication in Splunk Chapter 4: Splunk Forwarder Management Chapter 5: Splunk Index Management Chapter 6: Splunk Configuration Files Chapter 7: Exploring Distributed Search Part 2:Splunk Data Administration
Chapter 8: Getting Data In Chapter 9: Configuring Splunk Data Inputs Chapter 10: Data Parsing and Transformation Chapter 11: Field Extractions and Lookups Chapter 12: Self-Assessment Mock Exam Index Other Books You May Enjoy

Summary

This first chapter of Part 2 of the book aimed to get you started with Splunk data administration. We began with the introduction of data input types, including the file-based, network, agentless (HEC), and script-based options. There is also a special type of input that can be installed through TAs available from https://splunkbase.com. We also understood that these inputs are configured either by creating an inputs.conf file or through the Splunk CLI.

Afterward, we looked at the default metadata fields assigned by Splunk, along with their significance when searching data. The sourcetype field plays a crucial role in Splunk as it helps classify and categorize data by its source type. Splunk uses a pre-trained list of source types to automatically detect and assign the appropriate sourcetype if none is specified during the input phase. sourcetype definitions are configured in the props.conf file, where data administrators create custom ones based on the type of data they...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}