Time
1 hour 59 minutes
Difficulty
Beginner
CEU/CPE
2

Video Transcription

00:01
in this video will build on our search knowledge further to create reports and dashboards.
00:09
Reports are basically saved. Searches or pivots.
00:12
We haven't talked about pivots, but it's an alternative way of presenting data without using the ***. Search processing language.
00:21
When creating a pivot, you can select the rows and columns you want and play with different formatting and statistical options. It can be useful, but I think it's more important in the beginning to get used to using the Splunk search language.
00:35
Here are a couple of screen shots for a reference.
00:38
When you run a search, you could click
00:41
under statistics the pivot option.
00:44
And then it takes you to a screen like this where you have
00:47
a lot of different options for
00:49
changing how the data is prevented.
00:55
Reports can be scheduled, or you can run them when you feel like it.
00:59
You can also have a report. Trigger actions like an alert
01:04
dashboards can help you visualize and interact with data.
01:07
User could, for example, type in and submit a cured that returns events that matches
01:15
when a dashboard takes in user input. It can also be referred to as a form
01:21
APS with user interfaces have them in the form of dashboards, and you could make your own pretty easily.
01:27
You can use the Splunk interface for creating simple dashboards or dive into the simple external source code for more advanced changes.
01:36
You also have the option of converting a dashboard to HTML to work with.
01:41
With that introduction, let's get into *** and take a look.
01:46
I have a search here.
01:48
I was looking at the
01:49
disc usage on my splint server
01:53
to say that as a report, I'm gonna go to save as report
01:57
and type in Splunk
01:59
disc usage and go to save.
02:02
Now if I want to view it, I can click here.
02:12
And if I wanted to change the time frame, are we looking at? I could go up here.
02:15
I can also go here and do things like that. It permissions
02:20
so I can let
02:22
other people look at this,
02:25
and I can also add it. The schedule. So once I scheduled this, I have a few differ options come up.
02:35
I could, for example, said it to run every week,
02:38
a certain time and day
02:39
over a cross a certain time range.
02:45
I also have the option of setting a priority.
02:49
This is useful in cases where you may have multiple reports and searches going and don't have a powerful enough environment to run them all at once.
02:59
The schedule window option
03:00
down here lets me pick a time frame
03:05
where
03:06
Spawn Kim, pick one to run it
03:09
in order to improve the efficiency
03:13
of the searches and reports that are running.
03:15
If you have a report that you really only need once a day and a lot of other searches going,
03:22
you could tell it to run any time in this in one of these windows.
03:28
The scheduled
03:30
reports are very similar to alerts
03:32
here. We could add
03:35
a trigger action
03:37
of That's the same for an alert, such a sending an email
03:40
with the attached results.
03:45
We could also place this report inside a dashboard
03:49
to create a dashboard.
03:51
I can be in the search and reporting Ap and then click dashboards
03:58
and then I can click Create new dashboard,
04:00
and I'm just gonna name it here
04:06
and click create.
04:13
I'm going to stick to the user interface for this example,
04:15
but as you remember, you do have the option of modifying the source code.
04:21
One of the first things I may want to do is at a panel.
04:26
I could create a new one, or it could build one off the report we just made.
04:30
So if I show more,
04:32
I can add a ***. This usage report,
04:41
I could give it a name, and I can also play with the visualization
04:46
known. These are particularly useful for this search, but some of them are really good. Like
04:53
using the geo stats
04:55
option can be really good for a variety of things, like looking at the sources of Loggins. Or
05:02
you could
05:04
have a breakdown of the types of errors that you're seeing for a Pacific source type.
05:12
I'm gonna go ahead and add another panel and created new this time
05:16
off like statistics table,
05:20
and have it look at all time.
05:25
I'll leave the option of
05:27
using the time picker. And I'm just gonna add in a simple search here
05:34
this look that when those event logs and just doesn't event
05:39
count
05:40
by user name,
05:43
you gonna add this to the dashboard?
05:46
If I want, I can move these around. So if I think this one should be on top or maybe just off to the side of that. When I could do that,
05:56
and
05:58
for some of these formatting options, I could do something like
06:02
add an overlay of a heat map,
06:05
where it gives these higher number a darker color.
06:13
I can also add a user input, such as
06:17
time input, where they could select the time that they want for the results on this dashboard,
06:24
when they're set to pay attention to that
06:27
and for fun, I'm gonna change this to a dark theme and click save
06:32
and no, go ahead and refresh this
06:40
great. Here's our brand new dashboard
06:46
now.
06:47
Do you remember
06:50
what a dashboard that takes in user input can be called?
06:55
There's a specific word I'm looking for.
07:00
The answer's form. Dashboards can be made to let users click on options and enter in information
07:05
that changes what's presented on a dashboard.
07:10
In the next video, we'll cover some APP basics

Up Next

Introduction to Splunk

This Splunk training class is designed to quickly introduce you to Splunk and its many capabilities.

Instructed By

Instructor Profile Image
Natasha Staples
Incident Response Security Engineer at Arrow Electronics
Instructor