Using Fields (SUF)

 

Course Overview

This three-hour module is for power users who want to learn about fields and how to use fields in searches. Topics will focus on explaining the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields. The last topic will introduce how fields from other data sources can be used to enrich search results.

Who should attend

Splunk modules are designed for specific roles such as Splunk Administrator, Developer, User, Knowledge Manager, or Architect.

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Creating search queries
  • Knowledge objects

Course Objectives

Topic 1 – What are Fields?

  • Understand fields and field auto-extraction
  • Explore the Fields sidebar
  • Add fields to the Selected Fields list
  • Explore and generate reports from the Fields window


Topic 2 – What is Field Discovery?

  • Understand Field Discovery
  • Explore search modes and their effect on search results


Topic 3 – Using Fields in Searches

  • Use fields correctly in basic searches
  • Use fields with operators
  • Use the rename command
  • Use the fields command to improve search performance


Topic 4 – Comparing Temporary versus Persistent Fields

  • Differentiate between temporary and persistent fields
  • Create temporary fields with the eval command
  • Extract temporary fields with the erex and rex commands


Topic 5 – Enriching Data

  • Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data

Outline: Using Fields (SUF)

  • What are Fields?
  • What is Field Discovery?
  • Using Fields in Searches
  • Comparing Temporary versus Persistent Fields
  • Enriching Data

Prices & Delivery methods

Online Training

Duration
3 hours

Price
  • US$ 500
  • Splunk Training Units: 50 SPC
Classroom Training

Duration
3 hours

Price
  • United States: US$ 500
  • Splunk Training Units: 50 SPC
E-Learning
Price
  • United States: US$ 500

Click on town name or "Online Training" to book Schedule

This is an Instructor-Led Classroom course
Guaranteed date:   This green checkmark in the Upcoming Schedule below indicates that this session is Guaranteed to Run.
Instructor-led Online Training:   This is an Instructor-Led Online (ILO) course. These sessions are conducted via WebEx in a VoIP environment and require an Internet Connection and headset with microphone connected to your computer or laptop.
This is a FLEX course, which is delivered simultaneously in two modalities. Choose to attend the Instructor-Led Online (ILO) virtual session or Instructor-Led Classroom (ILT) session.

Italy

Guaranteed to Run Online Training Time zone: Europe/Rome Enroll
Rome This is a FLEX course. Enroll
Online Training Time zone: Europe/Rome Enroll
Milan This is a FLEX course. Enroll
Online Training Time zone: Europe/Rome Enroll