Course Content
This four hour module provides Splunk users in-depth information about metrics, ingesting and searching metrics data, and how to use the Metrics Workspace to analyze and create visualizations.
Prerequisites
Required:
- Fundamentals 1 (Retired)
- Fundamentals 2 (Retired)
- Splunk System Administration
Recommended:
- Splunk Data Administration
Course Objectives
- Metrics Overview
- Metrics Terminology
- Onboard Metrics Data
- Metrics Indexing
- Protocols to Ingest Metrics Data
- Metrics SPL Commands
- Log to metrics Conversion
- Use the Metrics Workspace
- Metrics Best Practices
Outline: Working with Metrics in Splunk (WWMS)
Topic 1 – Metrics Overview
- Overview of metrics data and terminology
- Review Splunk framework for metrics
- Discuss metrics use cases
Topic 2 – Onboarding Metrics Data
- Review metrics source types and protocols
- Describe metrics indexing
- Introduce rollup policies
- Review the process of ingesting metrics data
Topic 3 – Log to Metrics
- Create metrics data from events
- Create a log to metrics source type
- Ingest event and metrics data from log files
Topic 4 – Searching Metrics Data
- Search metrics data using SPL
- Review the Metrics Workspace
- Use the metrics workspace to analyze and visualize metrics data