Chapter 4. Knowledge Management

In this chapter we are going to learn some techniques to manage incoming data in your Splunk indexers, some basics on how to leverage those knowledge objects to enhance performance when searching, as well as the pros and cons of pre- and post-field extraction.

Now that we've learned how to get all of our data into Splunk in effective ways, the next question is How can I search for what I want? That is a loaded question with Splunk, because any ninja out there will answer that with the question, What do you want to see?

Understanding the basics of the search syntax, as well as search behavior, is a great way of understanding why you need to create events, fields, and lookups. Have you ever been to a Splunk event, ...

Get Splunk Best Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.