Logging indexing and visualization
Splunk is a software utility for machine log data collection, indexing, and visualization for “operational intelligence”. It is used to:
Collect and Index Log Data: Index streaming log data from all your distributed systems regardless of format or location.
Zoom in and out on timelines to automatically reveal trends, spikes and patterns and click to drill down into search results.
Splunk online documentation is located at: http://docs.splunk.com/Documentation/Splunk
Fundamentals courses are FREE at https://education.splunk.com/catalog?category=splunk-fundamentals-part-1
There is a different set of installation and set-up instructions depending on the edition:
Go to the Download page:
Splunk Light is meant for local install. Read about it at:
Download the “free trial”, which means that this is a licensed product.
Next to the “Free Splunk” at the right, click Download to URL:
Index 500 MB/Day.
wget -O splunk-7.1.0-2e75b3406c5b-darwin-64.tgz 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86&platform=macos&version=7.1.0&product=splunk&filename=splunk-7.1.0-2e75b3406c5b-darwin-64.tgz&wget=true'
The MD5 is at, for the version at time of writing: https://download.splunk.com/products/splunk/releases/7.1.0/osx/splunk-7.1.0-2e75b3406c5b-darwin-64.tgz.md5
PROTIP: Your free Splunk Enterprise license allows you to index up to 500MB per day for 60 days. You can convert to a perpetual Free license or purchase an Enterprise license after that period.
If you don’t have an account, register.
You may have to copy and paste the URL from above to get back to the page.
For release notes, refer to the Known issues in the Release Notes manual:
https://splunkbase.splunk.com/app/3138/ 3D Scatterplot - Custom Visualization is built with plotly.js, which combines WebGL and d3.js. So you can zoom, rotate, and orbit around the points, change aspect ratios, colors, sizes, opacity, labels, etc.
Currently, this visualization supports 50,000 points and does not limit your categorical values. Download the app to see some examples.
Splunk Operational Intelligence Cookbook By Josh Diakun, Paul R Johnson, Derek Mock
Blazemeter has additional software that only works on their cloud platform.
Splunk Learning Path
Installing and Configuring Splunk
Pluralsight video course: Optimizing Fields, Tags, and Event Types in Splunk [1h 36m] 28 Feb 2019 by Joe Abraham (@jobabrh, jobabrahamtech.com) is based on Splunk version 7.2.1
Performing Basic Splunk Searches
Analyzing Machine Data with Splunk