Splunk : Discussion on "Subsearches"

  Рет қаралды 18,001

Splunk & Machine Learning

Splunk & Machine Learning

Күн бұрын

Пікірлер: 17
@securiosityy
@securiosityy Жыл бұрын
Very well explained! I just couldn't understand why anyone would use sub searches. This makes much more sense now. Thank you!
@VadersWeekendHelmet
@VadersWeekendHelmet 3 жыл бұрын
I'm already 10 mins in and learned a lot. Subsearch was something I could never fully master even after year of using Splunk, but thanks for the video packed full of info!
@vipulsoman
@vipulsoman Жыл бұрын
Learnt a lot from your video, thank you
@vikashperiwal1498
@vikashperiwal1498 5 жыл бұрын
Nice explanation with a beautiful use case...
@etaihellman4591
@etaihellman4591 2 жыл бұрын
Amazing video!! Thank you again.!!
@dth546
@dth546 3 жыл бұрын
Thanks for the video. It helped me.
@vikassingh4320
@vikassingh4320 5 жыл бұрын
The Best.. As always
@wondl6608
@wondl6608 5 жыл бұрын
Thank you so much for the outstanding videos. I learned a lot from you . Thank you much !! Well explained and to the point . Any plans releasing videos on Splunk Enterprise security and ITSI. Thanks All the best
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you... Only thing is stopping me to cover itsi is its not free... And 7 days of sandbox is not enough... I sent an email to splunk but I don't think they will entertain my request for longer sandbox. I am thinking to cover the theory part first then use the sandbox for some demo
@HipHopHoller
@HipHopHoller 5 жыл бұрын
Outstanding video. Thank you!
@hectorcrespo1747
@hectorcrespo1747 3 жыл бұрын
Thanks, very useful video
@raju5081
@raju5081 4 жыл бұрын
Very good video. I have one question - For e.g. : Subsearch gives few accountIDs from different index and sourcetype. (Contains only order info) Main search needs those accountIDs to filter them out and show inactive accountIDs that did not place any orders yet Subsearch - has order info MainSearch - has account info index=account sourcetype=x NOT [ index=order sourcetype=y | fields accountID ] | table accountID is the above query correct ? what is the fastest way to get it ?
@splunk_ml
@splunk_ml 4 жыл бұрын
Yes the query looks correct. Fastest way would be if you can build a summary from the query result and use summary index in your reports or dashboards.
@donneakaleath9131
@donneakaleath9131 3 жыл бұрын
Thank you!
@venunair8337
@venunair8337 4 жыл бұрын
can you pls....start Splunk Enterprise security your videos are awesome
Splunk Commands : Discussion on "return" and "format" command
19:37
Splunk & Machine Learning
Рет қаралды 3,4 М.
Summary Indexing in Splunk
6:59
Splunk How-To
Рет қаралды 14 М.
Thank you mommy 😊💝 #shorts
0:24
5-Minute Crafts HOUSE
Рет қаралды 33 МЛН
Caleb Pressley Shows TSA How It’s Done
0:28
Barstool Sports
Рет қаралды 60 МЛН
Splunk : Discussion on Event types knowledge object & "findtypes" command
26:27
Splunk & Machine Learning
Рет қаралды 7 М.
Splunk Commands : Detail discussion on Streamstats and Eventstats Command
38:26
Splunk & Machine Learning
Рет қаралды 10 М.
Using Lookups in Splunk
9:43
Blue Team Consulting
Рет қаралды 10 М.
Splunk Commands : "join" vs "map" vs "selfjoin" command detail explanation
24:13
Splunk & Machine Learning
Рет қаралды 25 М.
Splunk Commands : How "transaction" command works
36:46
Splunk & Machine Learning
Рет қаралды 20 М.
Minimizing Inefficient Searches in Splunk
7:38
Splunk How-To
Рет қаралды 9 М.
Splunk Tips and Tricks | How to Join Two Sourcetypes Together
14:43
Creating Alerts in Splunk Enterprise
9:00
Splunk How-To
Рет қаралды 63 М.
Thank you mommy 😊💝 #shorts
0:24
5-Minute Crafts HOUSE
Рет қаралды 33 МЛН