I've written a lot of search in my time, and I regularly leverage a fairly deep understand of how Splunk stores and searches data to enable me to build faster and better searches. I've spent a lot of time verbally teaching these things to other folks, and recently was asked to build out an overview of how these capabilities work. That gave me the idea that we should have one consolidated place where someone can go from a normal Splunk user to an expert on Splunk's search design and process -- here that place is. Why is this on my website? Well, we'll probably make a blog post eventually, but as you read this it's incomplete. Maybe some day you'll come back and it will just be a pointer to a Splunk blog!
While there are a few pieces of content that are just being built now, Splunk has put out a lot of content over the years on how search actually works, and how to leverage that effectively for your needs. Most of the content below is from prior conf talks, from Splunk's Principal Sales Engineers and Software Developers.
I've broken out the content into Level 1, Level 2, and Level 3, so that you can judge how deep you want to, or need to go.
Public version not yet recorded. Check back for details, or get announcements by following @davidveuve.
David recommends watching the video first, then progressing to read the PDF copy and the flowchart.
Security Ninjutsu Part Four contains many different techniques at different levels. The techniques recommended for Level 1 fall under the "Intermediate Techniques" header in the slide deck, and include the following.
Public version not yet recorded. Check back for details, or get announcements by following @davidveuve.
Security Ninjutsu Part Four contains many different techniques at different levels. The techniques recommended for Level 2 fall under the "Advanced Techniques" header in the slide deck, and include the following.
Security Ninjutsu Part Four contains many different techniques at different levels. The techniques recommended for Level 3 fall under the "NINJA Techniques" header in the slide deck, and include the following.