SEARCH PROCESSING LANGUAGE (SPL)
PRIMER AND COOKBOOK
By David Carasso, Splunk’s Chief Mind
CITO
Research
New York, NY
,Exploring Splunk, by David Carasso
Copyright © 2012 by Splunk Inc.
All rights reserved. Printed in the United States of America.
Authorization to photocopy items for internal or personal use is granted
by Splunk, Inc. No other copying may occur without the express written
consent of Splunk, Inc.
Published by CITO Research, 1375 Broadway, Fl3, New York, NY 10018.
Editor/Analyst: Dan Woods, Deb Cameron
Copyeditor: Deb Cameron
Production Editor: Deb Gabriel
Cover: Splunk, Inc.
Graphics: Deb Gabriel
First Edition: April 2012
While every precaution has been taken in the preparation of this book,
the publisher and author assume no responsibility for errors or omissions
or for damages resulting from the use of the information contained herein.
ISBN: 978-0-9825506-7-0; 0-9825506-7-7
Disclaimer
This book is intended as a text and reference book for reading purposes
only. The actual use of Splunk’s software products must be in accordance
with their corresponding software license agreements and not with any-
thing written in this book. The documentation provided for Splunk’s soft-
ware products, and not this book, is the definitive source for information
on how to use these products.
Although great care has been taken to ensure the accuracy and timeliness
of the information in this book, Splunk does not give any warranty or
guarantee of the accuracy or timeliness of the information and Splunk does
not assume any liability in connection with any use or result from the use
of the information in this book. The reader should check at docs.splunk.
com for definitive descriptions of Splunk’s features and functionality.
, Table of Contents
Preface
About This Book i
What’s In This Book? ii
Conventionsii
Acknowledgmentsiii
PART I: EXPLORING SPLUNK
1 The Story of Splunk
Splunk to the Rescue in the Datacenter 3
Splunk to the Rescue in the Marketing Department 4
Approaching Splunk 5
Splunk: The Company and the Concept 7
How Splunk Mastered Machine Data in the Datacenter 8
Operational Intelligence 9
Operational Intelligence at Work 11
2 Getting Data In
Machine Data Basics 13
Types of Data Splunk Can Read 15
Splunk Data Sources 15
Downloading, Installing, and Starting Splunk 15
Bringing Data in for Indexing 17
Understanding How Splunk Indexes Data 18
3 Searching with Splunk
The Search Dashboard 23
SPL™: Search Processing Language 27