Time
1 hour 59 minutes
Difficulty
Beginner
CEU/CPE
2

Video Transcription

00:00
Hello and thanks for coming back.
00:02
I'm Natasha, and in the section, we're gonna answer the deceptively simple question of
00:07
what ISS Blunt
00:10
*** is. A company worth several $1,000,000,000 based out of San Francisco. It specializes in DD use In processing.
00:20
Split has multiple different products, But when you refer to just ***, people most often think of the *** platform and its core capabilities. Or they may just think about whatever they have set up at their company.
00:32
Splunk Enterprise. Blunt Cloud *** Free and *** light make up what is thought of as a sponsor platform,
00:39
and future videos will discuss the differences between these and talk about other products.
00:44
Course will focus on the common uses of the popular ***, enterprise and *** free and briefly cover the capabilities of other products that typically build on these platforms.
00:55
The company sums up his purpose as
00:57
***, turns machine data into answers
01:00
to dig a little deeper.
01:03
Splunk software aggregates processes, analyzes and help to use small the massive amounts of data.
01:08
It's particularly helpful for turning unstructured data in the usable information.
01:14
Some examples include ingesting authentication logs and alerting when there have been high volume failures.
01:21
Or he could collect Web traffic data and provide statistics on visitor activity.
01:26
Another example would be story instance like data until an admin search for information to troubleshoot a problem,
01:32
you could retrieve mouth or alerts and correlated with other activity.
01:36
Or use a look up to define error codes and organize a problem and human readable format.
01:42
Gather I ot data and provide meaningful metrics, Soren store information required for an audit and tons of other uses.
01:52
Splunk has a strong community built around its product, including forums, conferences and even local events. In many places, it's growth have exploded over the last few years, but it's found her back in 2003.
02:06
The easiest way to get a grasp on *** might be to take a quick look.
02:10
He's a relatively empty instance of spoiling enterprise. I have running our virtual machine.
02:16
I am searching for some data
02:20
just traffic on this machine, and I found 320 events in the last hour.
02:25
We're gonna look at a single event here, can pull this up and see the raw text
02:30
so this itself would be hard for us to work with
02:34
but our D. C. Here it breaks it out into different fields that I can then use
02:38
for other tasks.
02:40
So right here I could run a simple search Where I look at how many events have happened
02:49
in this data.
02:51
Ah, by app.
02:53
There we are.
03:00
So now we've got to our quiz. True or false *** can only handle parse data.
03:07
The answer is false. Swank is great for organizing raw data.
03:14
Some of what we've learned in this section. Spong takes data that's difficult to handle, maybe because there's so much of it or because it's unorganized or a meaningless on its own, and make that usable in a variety of ways, such as for reporting, alerting troubleshooting for hunting, making business decisions and so on.
03:34
In the next video, we're gonna be talking about *** in your career.
03:38
Thanks for watching

Up Next

Introduction to Splunk

This Splunk training class is designed to quickly introduce you to Splunk and its many capabilities.

Instructed By

Instructor Profile Image
Natasha Staples
Incident Response Security Engineer at Arrow Electronics
Instructor