SPLK-UFIELD - Using Fields

This three-hour course is for power users who want to learn about fields and how to use fields in searches. Topics will focus on explaining the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields. The last topic will introduce how fields from other data sources can be used to enrich search results.

Code: splk-ufield

Duration: 3.0 hours

Enquire Now

Start learning today!

Click Hereto customize your Training

Objectives

  • What are Fields
  • What is Field Discovery
  • Using Fields in Searches
  • Comparing Temporary versus Persistent Fields
  • Enriching Data

Content

Topic 1 – What are Fields?

  • Understand fields and field auto-extraction
  • Explore the Fields sidebar
  • Add fields to the Selected Fields list
  • Explore and generate reports from the Fields window

Topic 2 – What is Field Discovery?

  • Understand Field Discovery
  • Explore search modes and their effect on search results

Topic 3 – Using Fields in Searches

  • Use fields correctly in basic searches
  • Use fields with operators
  • Use the rename command
  • Use the fields command to improve search performance

Topic 4 – Comparing Temporary versus Persistent Fields

  • Differentiate between temporary and persistent fields
  • Create temporary fields with the eval command
  • Extract temporary fields with the erex and rex commands

Topic 5 – Enriching Data

  • Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data

Audience

Search Experts Knowledge Managers

Prerequisites

To be successful, students should have completed the following courses:

  • Search Under the Hood
  • Multivalue Fields
  • Creating Knowledge Objects

Certification

product-certification

Course Benefits

product-benefits
  • Career growth
  • Broad Career opportunities
  • Worldwide recognition from leaders
  • Up-to Date technical skills
  • Popular Certification Badges

Splunk Popular Courses

splk-sefs

This "Fast Start" course covers over 60 commands and functions and prepares students to be search experts.

splk-iiss

This course prepares security practitioners to use SOAR to respond to security incidents.

splk-dyd

This course focuses on creating inputs, chain searches, event annotations, and improving dashboard performance.

splk-introdyd

This course focuses on dashboard creation, including prototyping, the dashboard definition, layouts types, adding visualizations, and dynamic coloring.
Enquire Now
 
 
 
 
knN2ru
By clicking "Submit", I agree to the Terms Of Use and Privacy Policy