Hi,
Can someone suggest a good way (or a real good book) on how to learn splunk queries. any suggestions would be appreciated.
Thanks
This community-run site called GoSplunk is a pretty cool resource for people to check out Splunk searches contributed by other users. You should be able to get some ideas on how certain commands work and edit according to your own fields/values.
https://gosplunk.com/
Here are some previous posts with good suggestions:
I read these two books on amazon to get started:
Advanced Splunk
https://www.amazon.com/gp/product/1785884352/ref=oh_aui_search_detailpage?ie=UTF8&psc=1
Splunk Operational Intelligence Cookbook - Second Edition
https://www.amazon.com/gp/product/1785284991/ref=oh_aui_search_detailpage?ie=UTF8&psc=1
Thanks!