Skip to main content
  • Book
  • © 2020

Practical Splunk Search Processing Language

A Guide for Mastering SPL Commands for Maximum Efficiency and Outcome

Apress

Authors:

  • Serves as a quick reference for the most popular SPL commands
  • Provides detailed guidance on improving the performance of SPL commands
  • Teaches SPL through the use of numerous real-world examples

Buy it now

Buying options

eBook USD 34.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 44.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access

This is a preview of subscription content, log in via an institution to check for access.

Table of contents (9 chapters)

  1. Front Matter

    Pages i-xxi
  2. Introducing the Splunk Platform

    • Karun Subramanian
    Pages 1-38
  3. Calculating Statistics

    • Karun Subramanian
    Pages 39-79
  4. Using Time-Related Operations

    • Karun Subramanian
    Pages 81-111
  5. Grouping and Correlating

    • Karun Subramanian
    Pages 113-139
  6. Working with Fields

    • Karun Subramanian
    Pages 141-176
  7. Using Lookups

    • Karun Subramanian
    Pages 177-191
  8. Advanced SPL Commands

    • Karun Subramanian
    Pages 193-221
  9. Less-Common Yet Impactful SPL Commands

    • Karun Subramanian
    Pages 223-242
  10. Optimizing SPL

    • Karun Subramanian
    Pages 243-261
  11. Back Matter

    Pages 263-268

About this book

Use this practical guide to the Splunk operational data intelligence platform to search, visualize, and analyze petabyte-scale, unstructured machine data. Get to the heart of the platform and use the Search Processing Language (SPL) tool to query the platform to find the answers you need.

With more than 140 commands, SPL gives you the power to ask any question of machine data. However, many users (both newbies and experienced users) find the language difficult to grasp and complex. This book takes you through the basics of SPL using plenty of hands-on examples and emphasizes the most impactful SPL commands (such as eval, stats, and timechart). You will understand the most efficient ways to query Splunk (such as learning the drawbacks of subsearches and join, and why it makes sense to use tstats). You will be introduced to lesser-known commands that can be very useful, such as using the command rex to extract fieldsand erex to generate regular expressions automatically.

In addition, you will learn how to create basic visualizations (such as charts and tables) and use prescriptive guidance on search optimization. For those ready to take it to the next level, the author introduces advanced commands such as predict, kmeans, and cluster.





What You Will Learn
  • Use real-world scenarios (such as analyzing a web access log) to search, group, correlate, and create reports using SPL commands
  • Enhance your search results using lookups and create new lookup tables using SPL commands
  • Extract fields from your search results
  • Compare data from multiple time frames in one chart (such as comparing your current day application performance to the average of the past 30 days)
  • Analyze the performance of your search using Job Inspector and identify execution costs of various components of your search





Who This Book Is For


Application developers, architects, DevOps engineers, application support engineers, network operations center analysts, security operations center (SOC) analysts, and cyber security professionals who use Splunk to search and analyze their machine data
















Authors and Affiliations

  • Greater Minneapolis, USA

    Karun Subramanian

About the author

​Karun Subramanian is an IT operations expert and a Splunk certified architect. He is committed to helping IT organizations implement world-class observability by making use of machine-generated data. His IT career has spanned more than two decades, ranging from systems administrator to software engineer to IT director. Possessing deep expertise of the Splunk platform, he has assisted teams to solve complex problems in the area of DevOps, security, and business analytics. He has worked in engineering roles for firms including Wells Fargo Bank, Express Scripts, Federal Reserve Bank, and Optum.

Bibliographic Information

  • Book Title: Practical Splunk Search Processing Language

  • Book Subtitle: A Guide for Mastering SPL Commands for Maximum Efficiency and Outcome

  • Authors: Karun Subramanian

  • DOI: https://doi.org/10.1007/978-1-4842-6276-4

  • Publisher: Apress Berkeley, CA

  • eBook Packages: Business and Management, Apress Access Books, Business and Management (R0)

  • Copyright Information: Karun Subramanian 2020

  • Softcover ISBN: 978-1-4842-6275-7Published: 24 November 2020

  • eBook ISBN: 978-1-4842-6276-4Published: 24 November 2020

  • Edition Number: 1

  • Number of Pages: XXI, 268

  • Number of Illustrations: 134 b/w illustrations

  • Topics: Big Data, IT in Business, Statistics, general

Buy it now

Buying options

eBook USD 34.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 44.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access