Splunk Knowledge Object : detail discussion on "data model"

  Рет қаралды 50,814

Splunk & Machine Learning

Splunk & Machine Learning

Күн бұрын

Пікірлер: 68
@gregsmith2141
@gregsmith2141 3 жыл бұрын
This data model and data model acceleration tutorial is awesome! I have been a System Engineer for over 30 years (different industry) and his training is consistently superior to anything I have ever had. His methodology of discussing the topic at a high level and then diving into lower level details is a marvelous teaching style. The video and audio quality are excellent and his diction is good and very understandable. His use of screen shots and live demos is well done. I have watched MANY of his training videos and am thankful for them. Very tactical.
@splunk_ml
@splunk_ml 3 жыл бұрын
Thanks for your valuable feedback Greg 🙏
@valarmathijaganathan6694
@valarmathijaganathan6694 3 жыл бұрын
I have been watching your videos for the last 2 weeks and I find learning in your channel is crystal clear and I can have also gained an in-depth knowledge as well in every topic
@dilippanwar
@dilippanwar 5 жыл бұрын
Awesome video. Better than offical splunk lectures. Thanks for your valuable contribution.
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you Dilip. Please share this channel with your colleagues. I need you guys support.
@EViL3666
@EViL3666 4 жыл бұрын
Every time I search for a video tutorial on Splunk, I always hit your videos - So thank you for taking the time to create such a comprehensive set of videos, you've certainly made my learning/research easier. Consider me subscribed!
@splunk_ml
@splunk_ml 4 жыл бұрын
You're very welcome! Kelvin.
@nagp3600
@nagp3600 6 жыл бұрын
You are incredible.Your clarity and intention to encourage free learning is remarkable.
@splunk_ml
@splunk_ml 6 жыл бұрын
Thank you ☺️
@dinakarn2770
@dinakarn2770 2 жыл бұрын
I love the way of your teaching and i got full information about data models
@aaoouch
@aaoouch 5 жыл бұрын
I have been looking for something like this for a long time. Thanks for creating such an excellent content
@anonymoussaif7361
@anonymoussaif7361 Жыл бұрын
Really super and well explain each and every thing on data model
@simple-security
@simple-security Жыл бұрын
Do you talk about Data Model ingestion costs anywhere in your videos? Is there a query or dashboard that helps monitor costs associated with your data models (with and without acceleration enabled)? Thank you.
@obinnaekeh9188
@obinnaekeh9188 2 жыл бұрын
Thanks for the video. Your channel is awesome
@madhurimayank8982
@madhurimayank8982 3 жыл бұрын
Thank you for this nice video. I had a question here, for example, if in my dashboard i am using an events generated from datamodel whose acceleration range is set to 30 days. What will be the impact if i select 60 days from the timerange picker from the dashboard ?
@anoopramachandran5197
@anoopramachandran5197 6 жыл бұрын
Great video Siddhartha!!! Thank you for doing this.
@splunk_ml
@splunk_ml 6 жыл бұрын
welcome Anoop :)
@vershsingh7120
@vershsingh7120 3 жыл бұрын
Hi Sid, I am not able see the Country Code filed in lookup table of Data model. As I've added it in setting>lookup>addfile. Also provide global permission.
@nitinat3590
@nitinat3590 4 жыл бұрын
Excellent discussion! Thanks for sharing.
@korablack2511
@korablack2511 6 жыл бұрын
Thank you so much for this, you are clearly a ninja !
@vershsingh7120
@vershsingh7120 3 жыл бұрын
I am not able see the Country Code filed in lookup table of Data model. As I've added it in setting>lookup>addfile. Also provide global permission. while I can search in normal search & Reporting through input look up command.
@jayachandrandhoni4928
@jayachandrandhoni4928 5 жыл бұрын
Simple and more informative.. Thanks buddy
@splunk_ml
@splunk_ml 5 жыл бұрын
Thanks man 👍
@amosadomowim6037
@amosadomowim6037 Жыл бұрын
Hi, quick question, when you clicked on 'pivot' on the dataset window, and then clicked on the continent, it showed "distinct Count of Continent" as 6 but mine showed "count of continent' as 9551. Any reason why I'm getting count instead of distinct count? Thanks.
@amosadomowim6037
@amosadomowim6037 Жыл бұрын
Nevermind sir, figured it out.
@valarmathijaganathan6694
@valarmathijaganathan6694 3 жыл бұрын
Could it be possible to create some scenario-based interview questions on Splunk?
@guilhermecervo1560
@guilhermecervo1560 2 жыл бұрын
Hello, I'm facing a problem with role restriciton in searchs with accelerated Datamodels, maybe you could help me. I applied the restriction in the role and everything was working perfect, even with searchs in datamodel. However, when I accelerated my datamodel, the role restriction filters stopped working. I'm imaging that it was due to the tsidx files generated by acceleration. Do you have any idea how can I apply such restriction even in accelerated datamodels?
@DirectionNext
@DirectionNext 4 жыл бұрын
At the video timeline 20:22, I followed the exact procedure. However, the country is not appearing in the interesting field. How did you get this?
@splunk_ml
@splunk_ml 4 жыл бұрын
did you created the lookup correctly? Then it should create the country field as well.
@pinkushgaba4003
@pinkushgaba4003 4 жыл бұрын
Thank you for this great lesson. I have to make a pivot showing monthly count. I am stuck at trying to extract month from a date field as a calculated field using eval command. Is it possible to do that in a data model? I have to make a pivot showing monthly count. Also, If I have a filter on the dashboard page for all the panels, how can i add that filter to function with the pivot?
@splunk_ml
@splunk_ml 4 жыл бұрын
In datamodel you can add eval field, using that you can extract month. I have discussed eval field as well in my video. Regarding your second question there is a pivot command which you can used in your dashboard.
@suvasreechatterjee6588
@suvasreechatterjee6588 5 жыл бұрын
Hi sir I have created Country field and in splunk but not showing country in add data drop down under datamodel
@haogedeng8842
@haogedeng8842 4 жыл бұрын
Thank you so much sir for sharing, very helpful!
@shenazgilani6370
@shenazgilani6370 5 жыл бұрын
very well explained ..Wondering about transaction dataset ..?
@splunk_ml
@splunk_ml 5 жыл бұрын
I am yet to create a video for that...I will be posting soon ☺️
@Sandeep223358
@Sandeep223358 4 жыл бұрын
Is it similar to the Splunk Common Information Model? If yes do we need to install the ad-on to do all the stuff in the video lecture?Thanks
@splunk_ml
@splunk_ml 4 жыл бұрын
Data models are used in CIM app. You no need to install CIM for this tutorial. Data Model is feature of Splunk.
@Sandeep223358
@Sandeep223358 4 жыл бұрын
@@splunk_ml Thanks for your reply. Do we use data models only in CIM app?
@splunk_ml
@splunk_ml 4 жыл бұрын
no no....data models can be used at dashboards or create pivot reports as well.
@Sandeep223358
@Sandeep223358 4 жыл бұрын
Splunk & Machine Learning Thanks again for your reply. Last question, CIM is used only for normalizing data with built in data models right? Can we create our own data models in CIM? Is there any tutorial from your side on this CIM concept?
@saikiranpinnamshetty1205
@saikiranpinnamshetty1205 4 жыл бұрын
hey Sid, quick question on DM I have cloned Authentication data model (not accelerated) , and added my few needy fields when I tried to use that in my search query I'm getting 0 results |tstats count as count values(Authentication_clone.user) as user values(Authentication_clone.Account_Name) as Account_Name where datamodel=Authentication_clone.Authentication where Authentication_clone.signature_id=4624 anything I'm missing here
@splunk_ml
@splunk_ml 4 жыл бұрын
you mean from the CIM application you cloned the DM? In that case you need to create corresponding tags and extract corresponding fields so that the DM can understand your data.Please have a look at the video I created for CIM. kzbin.info/www/bejne/fpXVcnqErrCoidU
@manigandanumapathy4840
@manigandanumapathy4840 5 жыл бұрын
Well explained. Thanks sir again!!
@TheGopinath369
@TheGopinath369 4 жыл бұрын
Can you please make a video how to configure and migrate the Splunk data into smartstore
@valarmathijaganathan6694
@valarmathijaganathan6694 3 жыл бұрын
When I upload the Zomato.csv file in Splunk it shows me in a corrupted format. What should I do and even the country code as well?
@splunk_ml
@splunk_ml 3 жыл бұрын
I will check the github and let you know
@rajurana6949
@rajurana6949 Жыл бұрын
eval continent=case(Country IN ("India", "Indonesia","Phillipines", "Singapore","Qatar", "Sri Lanka","Turkey","UAE"), "Asia", Country IN ("Australia","New Zealand"), "Oceania", Country IN ("Brazil"), "South America", Country IN ("Canada","United States"), "North America", Country IN ("South Africa"), "Africa", Country IN ("United Kingdom"), "Europe")
@yogigolla
@yogigolla 6 жыл бұрын
Excellent sir ! Thanks !
@varun-bigdataanalytics4892
@varun-bigdataanalytics4892 4 жыл бұрын
Hello, I want to understand the integration of css and js in splunk in depth(Basically want to enhance the look of my dashboards). Could you please share the videos if you have for the same?
@nishadt
@nishadt 5 жыл бұрын
As always excellent video Sid, I am still confused little accelaration and how summary data is built, high time for Splunk Analytics for Hadoop video.
@splunk_ml
@splunk_ml 5 жыл бұрын
Thanks Nishad. I will see if I can set it up, will try to cover that.
@krishnapriyadharshini4038
@krishnapriyadharshini4038 6 жыл бұрын
Thanks for making this video..
@__goyal__
@__goyal__ 4 жыл бұрын
Thank you for the easy explanation!
@ngotrongnghia9928
@ngotrongnghia9928 2 жыл бұрын
It seems there should be some steps we missed here. Because even I can inputlookup countrycode and zomato as well from search, unfortunately Splunk doesn't show "Country Code" field in the side bar. So could you please kindly help to clarify me on this?
@ngotrongnghia9928
@ngotrongnghia9928 2 жыл бұрын
also if using countrycode in .xls format, when creating lookups, my Splunk is crashed (Splunk version 8.2.4). I have to convert it to .csv.
@splunk_ml
@splunk_ml 2 жыл бұрын
yes splunk doesnt support .xls as lookup file, its needs to be csv. Also regarding your first question are still facing the issue?
@vasthavreddy2264
@vasthavreddy2264 3 жыл бұрын
Hi sir I need that country code Excel sheet to practice Can you please provide me that sheet
@madhavam274
@madhavam274 6 жыл бұрын
Good video thanks
@ronkoss814
@ronkoss814 3 жыл бұрын
Great tutorial. And you can use the video as a drinking game as well: drink a shot whenever the author says "ok". ;-)
@splunk_ml
@splunk_ml 3 жыл бұрын
🤣🤣🤣 this is very old video...I get rid of that bad habit recently....but amazing idea ...I will try one day 😆
@tatifor9624
@tatifor9624 4 жыл бұрын
Studiying justo from these 14 videos is enough to get my power user certification? Can someone help me on that?
@splunk_ml
@splunk_ml 4 жыл бұрын
Hello, I would suggest you have a look at the below video where I discussed about different splunk certifications kzbin.info/www/bejne/kKirp5KmbKede7c In the video description you will find the github link for an excel file... For each certification path I have added and still adding the KZbin video link of this channel. Hopefully that will be useful. github.com/siddharthajuprod07/youtube/tree/master/splunk_certification_path
@amarkondraju1379
@amarkondraju1379 5 жыл бұрын
Hatsoff sir
@narendrajha2628
@narendrajha2628 5 жыл бұрын
Thank you helpful
@timlindgren478
@timlindgren478 5 жыл бұрын
ok. :)
Splunk Commands : Discussion on Top & Rare command
13:16
Splunk & Machine Learning
Рет қаралды 4,6 М.
Splunk Knowledge Object: Detail discussion on Summary Index
51:18
Splunk & Machine Learning
Рет қаралды 25 М.
小丑揭穿坏人的阴谋 #小丑 #天使 #shorts
00:35
好人小丑
Рет қаралды 52 МЛН
PIZZA or CHICKEN // Left or Right Challenge
00:18
Hungry FAM
Рет қаралды 15 МЛН
За кого болели?😂
00:18
МЯТНАЯ ФАНТА
Рет қаралды 2 МЛН
СКОЛЬКО ПАЛЬЦЕВ ТУТ?
00:16
Masomka
Рет қаралды 2,5 МЛН
Working with Data Models in Splunk
22:13
Kinney Group
Рет қаралды 2,2 М.
Splunk Commands : Everything to know about "eval" command
49:26
Splunk & Machine Learning
Рет қаралды 80 М.
Splunk: Mapping to the CIM with Splunkable
39:00
Ableversity
Рет қаралды 1,8 М.
Splunk Data Models - Why Should You Use Them?
9:23
Lame Creations
Рет қаралды 12 М.
Splunk Commands : "join" vs "map" vs "selfjoin" command detail explanation
24:13
Splunk & Machine Learning
Рет қаралды 24 М.
Splunk : Discussion on "Subsearches"
27:58
Splunk & Machine Learning
Рет қаралды 17 М.
Splunk : Discussion on Event types knowledge object & "findtypes" command
26:27
Splunk & Machine Learning
Рет қаралды 6 М.
Splunk Data Models and How to Leverage EventTypes
18:24
Lame Creations
Рет қаралды 3,1 М.
How to accelerate in Splunk
17:55
Blue Team Consulting
Рет қаралды 2 М.
Дешёвые мониторы - имба?😳
0:59
Корнеич
Рет қаралды 1,9 МЛН
Как подключить магнитолу?
0:51
KS Customs
Рет қаралды 1,9 МЛН
Не бойтесь экраны "водопады"
1:00
Бананикс
Рет қаралды 365 М.