if i had to write a document for myself on basic learning of splunk: to create a dashboard i can either use inputs like index,source,source fields or I can give a data set is that right? for that can i write it like this or am i wrong with side headings:
I wanted to see what i captured is in right direction its for own sake,can i say like that like there are two ways for creating dashboard understand through inputs and other through data models?
Hi @Tron-spectron47,
everything in Splunk is a search, so you have to learn how to create a search, both using indexes or Data Models.
When you'll be able to create a search, you can save it in a dashboard or an alert or a report, but the starting point is always a search.
To start, you could follow the Splunk Search Tutorial https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial
Ciao.
Giuseppe
Hi @Tron-spectron47,
here you can find all the Splunk courses: https://www.splunk.com/en_us/training/course-catalog.html
in details you should see these courses:
Splunk Enterprise System Administration chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.splunk.com/en_us/pdfs/training/splunk-enterprise-system-administration-course-descriptio...
Splunk Enterprise Data Administration chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.splunk.com/en_us/pdfs/training/splunk-enterprise-data-administration-course-description....
Data Models chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.splunk.com/en_us/pdfs/training/data-models-course-description.pdf
You can find the page to register in the first url.
Ciao.
Giuseppe