SlideShare a Scribd company logo
Splunk Education Services
Advanced Searching and Reporting with Splunk 5.0
This nine-hour course supplements the Searching and Reporting
with Splunk class. It focuses on more advanced search and reporting
commands. Scenario-based examples and hands-on challenges
enable users to create robust searches, reports, and charts. Students
are coached step by step through complex searches to produce final
results. Major topics include the Splunk search process, using sub-
searches, using additional statistical commands and functions,
formatting and calculating results, charting commands and options,
correlating events, enriching data with lookups, and more.
Course Topics
 Beyond Search Fundamentals
 Using Sub-searches
 Using Advanced Statistics, Data Manipulation, & Filtering
 Using Advanced Charting
 Sorting, Searching and Reformatting Time
 Using Advanced Transactions
 Using Advanced Lookups
Course Prerequisites
Using Splunk and Searching and Reporting with Splunk courses
Class Format
Instructor-led lecture with labs. Delivered via virtual classroom or at
your site.
Course Objectives
Lesson 1 – Beyond Search Fundamentals
 Using the proper case in searches
 Describing Splunk’s search process
 Using the search inspector to view search performance
 Using the search inspector to troubleshoot searches
Lesson 2 – Using Sub-Searches
 Using sub-searches to correlate data
 Finding events that match values from a sub-search
 Finding events that do not match values from a sub-search
Lesson 3 – Using Advanced Statistics
 Using the appendpipe command
 Using statistical functions such as min, max, mean, median, and
standard deviation
 Using the streamstats command
 Using the eventstats command
Lesson 4 – Using Data Manipulation, and Filtering
 Using functions of the where command
 Using functions of the eval command
Lesson 5– Using Advanced Charting
 Using the addtotals command
 Using the rangemap command
 Using the append command
Lesson 6 – Sorting, Searching, and Reformatting Time
 Using time modifiers
 Searching for events using custom time ranges
 Searching for events within a window of time
 Displaying and use using relative dates
 Using custom time ranges in multiple sub-searches
Lesson 7 – Using Advanced Transactions
 Finding events logged before a particular event occurs
 Finding events logged after a particular event occurs
 Comparing complete transactions
 Analyzing transactions
Lesson 8 – Using Advanced Lookups
 Using lookup tables to include or exclude events
 Using time-based lookups
 Configuring time-based lookups
 Using lookups in alerts
Splunk Education Tracks
User: For all day-to-day Splunk users including customer support
staff, developers, systems administrators and management.
Administrator: For administrators of Splunk itself. (Administrators of
other systems who will just be using Splunk should take the User
track.)
Architect: For architects who will be designing Splunk
deployments, including architects on staff at customer
deployments, as well as partner professional services personnel.
Developer: For developers who will integrate, customize and
extend Splunk using its XML templates and advanced configuration
bundling.
Support Engineer: For Splunk OEM and channel partner support
staff who will be providing first line support for Splunk.
Tracks User Administrator Architect Developer
Support
Engineer
Using Splunk ✓ ✓ ✓ ✓ ✓
Searching and
Reporting with Splunk
✓ ✓ ✓ ✓
Advanced Searching
and Reporting with
Splunk
✓ ✓ ✓ ✓
Administrating Splunk ✓ ✓ ✓
Advanced Splunk
Administration
✓ ✓ ✓
Architecting and
Deploying Splunk
✓ ✓
Developing Apps with
Splunk
✓ ✓ ✓
Splunk Architect
Certification Lab
✓
Supporting Splunk ✓
Splunk Education Services
About Splunk
Splunk is software that indexes,
manages and enables you to search
data from any application, server or
network device in real time.
Visit our website at www.splunk.com
to download your own free copy.
Splunk Inc.
250 Brannan
San Francisco, CA 94107
866.GET.SPLUNK
(866.438.7758)
sales@splunk.com
support@splunk.com

More Related Content

PPTX
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
PDF
Threat Hunting with Elastic at SpectorOps: Welcome to HELK
PPTX
Splunk for Developers
PPTX
Getting Started with Splunk Enterprise Hands-On
PPTX
University of Alberta Customer Presentation
PPTX
Power of Splunk Search Processing Language (SPL) ...
PPTX
Splunk for Machine Learning and Analytics
PPTX
Machine Learning and Analytics Breakout Session
Splunk Fundamentals: Investigations with Core Splunk - Splunk Tech Day
Threat Hunting with Elastic at SpectorOps: Welcome to HELK
Splunk for Developers
Getting Started with Splunk Enterprise Hands-On
University of Alberta Customer Presentation
Power of Splunk Search Processing Language (SPL) ...
Splunk for Machine Learning and Analytics
Machine Learning and Analytics Breakout Session

What's hot (20)

PPTX
Group Health Cooperative Customer Presentation
PPTX
AdvancedMD Customer Presentation
PPTX
SQRRL threat hunting platform
PPTX
Building Splunk Apps, Development Paths with Splunk & User Behaviour Analytics
PDF
Machine Learning for Incident Detection: Getting Started
PDF
Fighting cybersecurity threats with Apache Spot
PPTX
Splunk for Enterprise Security featuring User Behavior Analytics
PPTX
Splunk User Group Edinburgh - November Event
PDF
Get full visibility and find hidden security issues
PPTX
WestJet Customer Presentation
PPTX
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
PPTX
Getting Started with Splunk Enterprise Hands-On Breakout Session
PPTX
SplunkLive! Frankfurt 2018 - Monitoring the End User Experience with Splunk
PPTX
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
PPTX
Nicola Pagni - Anomaly Detection in Elasticsearch
PPTX
Machine Learning + Analytics in Splunk
PDF
SplunkLive! Frankfurt 2018 - Customer Presentation: Bosch Cyber Defense Center
PPTX
Power of Splunk Search Processing Language (SPL)
PPTX
SplunkLive! Customer Presentation - Cisco Systems, Inc.
PDF
Security Insights at Scale
Group Health Cooperative Customer Presentation
AdvancedMD Customer Presentation
SQRRL threat hunting platform
Building Splunk Apps, Development Paths with Splunk & User Behaviour Analytics
Machine Learning for Incident Detection: Getting Started
Fighting cybersecurity threats with Apache Spot
Splunk for Enterprise Security featuring User Behavior Analytics
Splunk User Group Edinburgh - November Event
Get full visibility and find hidden security issues
WestJet Customer Presentation
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
Getting Started with Splunk Enterprise Hands-On Breakout Session
SplunkLive! Frankfurt 2018 - Monitoring the End User Experience with Splunk
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
Nicola Pagni - Anomaly Detection in Elasticsearch
Machine Learning + Analytics in Splunk
SplunkLive! Frankfurt 2018 - Customer Presentation: Bosch Cyber Defense Center
Power of Splunk Search Processing Language (SPL)
SplunkLive! Customer Presentation - Cisco Systems, Inc.
Security Insights at Scale
Ad

Viewers also liked (19)

PPTX
Operational Security
PPTX
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
PPTX
SplunkLive! Advanced Session
PDF
SPLUNK Power User Certification
PDF
Splunk .conf2011: Splunk for Fraud and Forensics at Intuit
PDF
Molina Healthcare Customer Presentation
PDF
Splunk Enterprise for InfoSec Hands-On
DOC
Renuka Prasad CV
PDF
CV Phil Green, Chicago, London
DOCX
C C Resume
DOCX
DEEPANSHU_Resume
PDF
Administering Splunk course
PDF
Using Splunk course outline
DOC
LvR-CV-2016
PDF
wfs_resume
PDF
Insider Threat Detection Recommendations
PDF
PR Lieberman Sailpoint Partnership_SailPoint FINAL
DOCX
RESUME_SaranyaNagaraj_A
PDF
Splunk Searching and reporting 43course
Operational Security
Visualizing the Insider Threat: Challenges and tools for identifying maliciou...
SplunkLive! Advanced Session
SPLUNK Power User Certification
Splunk .conf2011: Splunk for Fraud and Forensics at Intuit
Molina Healthcare Customer Presentation
Splunk Enterprise for InfoSec Hands-On
Renuka Prasad CV
CV Phil Green, Chicago, London
C C Resume
DEEPANSHU_Resume
Administering Splunk course
Using Splunk course outline
LvR-CV-2016
wfs_resume
Insider Threat Detection Recommendations
PR Lieberman Sailpoint Partnership_SailPoint FINAL
RESUME_SaranyaNagaraj_A
Splunk Searching and reporting 43course
Ad

Similar to Splunk Advanced searching and reporting Class description (20)

PDF
Splunk Searching and Reporting Class Details
PDF
Using splunk43course
PDF
Advanced Splunk 50 administration
PDF
Advanced Splunk Administration
PDF
Learn splunk online training
PDF
Administering splunk 43 course
PPT
Splunk .conf2011: Search Language: Beginner
PPTX
Getting started with Splunk - Break out Session
PPTX
Getting started with Splunk
PPTX
SplunkLive! Beginner Session
PDF
SplunkLive! Washington DC May 2013 - Search Language Beginner
DOCX
Veera
PPTX
Getting Started Getting Started With Splunk Enterprise
PPTX
Getting Started with Splunk Break out Session
PPTX
Splunk live beginner training nyc
PPTX
Splunk bsides
PPTX
SplunkLive! Getting Started with Splunk Enterprise
PPTX
SplunkLive! Zurich 2017 - Getting Started with Splunk Enterprise
PDF
Getting Started Breakout Session
PPTX
SplunkLive! London 2016 Getting started with Splunk
Splunk Searching and Reporting Class Details
Using splunk43course
Advanced Splunk 50 administration
Advanced Splunk Administration
Learn splunk online training
Administering splunk 43 course
Splunk .conf2011: Search Language: Beginner
Getting started with Splunk - Break out Session
Getting started with Splunk
SplunkLive! Beginner Session
SplunkLive! Washington DC May 2013 - Search Language Beginner
Veera
Getting Started Getting Started With Splunk Enterprise
Getting Started with Splunk Break out Session
Splunk live beginner training nyc
Splunk bsides
SplunkLive! Getting Started with Splunk Enterprise
SplunkLive! Zurich 2017 - Getting Started with Splunk Enterprise
Getting Started Breakout Session
SplunkLive! London 2016 Getting started with Splunk

More from Greg Hanchin (20)

PDF
NUTANIX and SPLUNK
PDF
Splunk for exchange
PDF
Splunk for cyber_threat
PDF
Splunk for compliance
PDF
Advanced searching and reporting 50 course
PPTX
Splunk FISMA for Continuous Monitoring
PDF
Splunk forwarders tech_brief
PDF
Splunk and map_reduce
PDF
Splunk for xen_desktop
PDF
Splunk for palo_alto
PDF
Splunk for ibtrm
PDF
Splunk for fisma
PDF
Splunk for f5
PDF
Splunk for db_connect
PDF
Splunk for active_directory
PDF
Splunk app for_windows
PDF
Splunk app for_enterprise_security
PDF
Splunk guide for_iso_27002
PDF
Splunk for security
PDF
Splunk for exchange
NUTANIX and SPLUNK
Splunk for exchange
Splunk for cyber_threat
Splunk for compliance
Advanced searching and reporting 50 course
Splunk FISMA for Continuous Monitoring
Splunk forwarders tech_brief
Splunk and map_reduce
Splunk for xen_desktop
Splunk for palo_alto
Splunk for ibtrm
Splunk for fisma
Splunk for f5
Splunk for db_connect
Splunk for active_directory
Splunk app for_windows
Splunk app for_enterprise_security
Splunk guide for_iso_27002
Splunk for security
Splunk for exchange

Recently uploaded (20)

PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
KodekX | Application Modernization Development
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Encapsulation theory and applications.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Approach and Philosophy of On baking technology
PPTX
Spectroscopy.pptx food analysis technology
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
cuic standard and advanced reporting.pdf
PPTX
Cloud computing and distributed systems.
PDF
Machine learning based COVID-19 study performance prediction
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Per capita expenditure prediction using model stacking based on satellite ima...
KodekX | Application Modernization Development
Mobile App Security Testing_ A Comprehensive Guide.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Encapsulation theory and applications.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Approach and Philosophy of On baking technology
Spectroscopy.pptx food analysis technology
Spectral efficient network and resource selection model in 5G networks
Network Security Unit 5.pdf for BCA BBA.
Programs and apps: productivity, graphics, security and other tools
cuic standard and advanced reporting.pdf
Cloud computing and distributed systems.
Machine learning based COVID-19 study performance prediction
sap open course for s4hana steps from ECC to s4
Unlocking AI with Model Context Protocol (MCP)
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
“AI and Expert System Decision Support & Business Intelligence Systems”

Splunk Advanced searching and reporting Class description

  • 1. Splunk Education Services Advanced Searching and Reporting with Splunk 5.0 This nine-hour course supplements the Searching and Reporting with Splunk class. It focuses on more advanced search and reporting commands. Scenario-based examples and hands-on challenges enable users to create robust searches, reports, and charts. Students are coached step by step through complex searches to produce final results. Major topics include the Splunk search process, using sub- searches, using additional statistical commands and functions, formatting and calculating results, charting commands and options, correlating events, enriching data with lookups, and more. Course Topics  Beyond Search Fundamentals  Using Sub-searches  Using Advanced Statistics, Data Manipulation, & Filtering  Using Advanced Charting  Sorting, Searching and Reformatting Time  Using Advanced Transactions  Using Advanced Lookups Course Prerequisites Using Splunk and Searching and Reporting with Splunk courses Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site. Course Objectives Lesson 1 – Beyond Search Fundamentals  Using the proper case in searches  Describing Splunk’s search process  Using the search inspector to view search performance  Using the search inspector to troubleshoot searches Lesson 2 – Using Sub-Searches  Using sub-searches to correlate data  Finding events that match values from a sub-search  Finding events that do not match values from a sub-search Lesson 3 – Using Advanced Statistics  Using the appendpipe command  Using statistical functions such as min, max, mean, median, and standard deviation  Using the streamstats command  Using the eventstats command Lesson 4 – Using Data Manipulation, and Filtering  Using functions of the where command  Using functions of the eval command Lesson 5– Using Advanced Charting  Using the addtotals command  Using the rangemap command  Using the append command Lesson 6 – Sorting, Searching, and Reformatting Time  Using time modifiers  Searching for events using custom time ranges  Searching for events within a window of time  Displaying and use using relative dates  Using custom time ranges in multiple sub-searches Lesson 7 – Using Advanced Transactions  Finding events logged before a particular event occurs  Finding events logged after a particular event occurs  Comparing complete transactions  Analyzing transactions Lesson 8 – Using Advanced Lookups  Using lookup tables to include or exclude events  Using time-based lookups  Configuring time-based lookups  Using lookups in alerts Splunk Education Tracks User: For all day-to-day Splunk users including customer support staff, developers, systems administrators and management. Administrator: For administrators of Splunk itself. (Administrators of other systems who will just be using Splunk should take the User track.) Architect: For architects who will be designing Splunk deployments, including architects on staff at customer deployments, as well as partner professional services personnel. Developer: For developers who will integrate, customize and extend Splunk using its XML templates and advanced configuration bundling. Support Engineer: For Splunk OEM and channel partner support staff who will be providing first line support for Splunk. Tracks User Administrator Architect Developer Support Engineer Using Splunk ✓ ✓ ✓ ✓ ✓ Searching and Reporting with Splunk ✓ ✓ ✓ ✓ Advanced Searching and Reporting with Splunk ✓ ✓ ✓ ✓ Administrating Splunk ✓ ✓ ✓ Advanced Splunk Administration ✓ ✓ ✓ Architecting and Deploying Splunk ✓ ✓ Developing Apps with Splunk ✓ ✓ ✓ Splunk Architect Certification Lab ✓ Supporting Splunk ✓
  • 2. Splunk Education Services About Splunk Splunk is software that indexes, manages and enables you to search data from any application, server or network device in real time. Visit our website at www.splunk.com to download your own free copy. Splunk Inc. 250 Brannan San Francisco, CA 94107 866.GET.SPLUNK (866.438.7758) sales@splunk.com support@splunk.com