Splunk Search

How to get to grips with SPL.

JPurdham
Engager

Hi guys,

I'm new to splunk, and we have recently implemented splunk enterprise in our environment. We are primarily looking at using "splunk app for windows infrastructure" for DPA requirements. We currently have one server doing everything (windows server 2012R2 12GB RAM 12CPU) running in a visualised environment, VMware.

I have configured our DC's to be universal forwarders and have set up the data inputs so I can search and query the data along with creating reports and alerts. Can you help me get to grips with SPL? The only other language I know is PowerShell, is there any documentation/video's or cheat sheets on SPL?

I have watched the Pluralsight courses on splunk, however these are more of an introduction to splunk and not as in-depth as I need, although they are useful.

Thanks in advance,
Jake

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

On top of docs.splunk.com and splunk's own training there are books as well, first and foremost the epic and free splunk.com/goto/book - older, but mostly still relevant in terms of SPL.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

On top of docs.splunk.com and splunk's own training there are books as well, first and foremost the epic and free splunk.com/goto/book - older, but mostly still relevant in terms of SPL.

sheamus69
Communicator

Martins advice, above, is excellent. As an addition to the suggested resources, I would recommend the Splunk Quick Reference guide - I have a laminated copy at my desk as an aid to memory.

http://docs.splunk.com/images/4/4f/Splunk_Quick_Reference_Guide_6.x.pdf

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...