This chapter provided an introduction to the most common knowledge objects Splunk users can leverage to enhance their data. We learned how to extract and create new fields in events, how to group and/or replace search criteria with event types and macros, how to tag and categorize event fields with tags and aliases, and how to enhance the data in event fields with lookups. Then, we looked at creating datasets and data models to be used in pivot tables so our less technical users can leverage the power of the data provided by Splunk in their reports and dashboards. In the next chapter, we'll cover how to create reports, dashboards, and alerts – see you there!
Germany
Slovakia
Canada
Brazil
Singapore
Hungary
Philippines
Mexico
Thailand
Ukraine
Luxembourg
Estonia
Lithuania
Norway
Chile
United States
Great Britain
India
Spain
South Korea
Ecuador
Colombia
Taiwan
Switzerland
Indonesia
Cyprus
Denmark
Finland
Poland
Malta
Czechia
New Zealand
Austria
Turkey
France
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Malaysia
South Africa
Netherlands
Bulgaria
Latvia
Australia
Japan
Russia