SPLK-SOPZ - Search Optimization

This three-hour course is for power users who want to improve search performance. Topics will cover how search modes affect performance, how to create an efficient basic search, how to accelerate reports and data models, and how to use the tstats command to quickly query data.

Code: splk-sopz

Duration: 3.0 hours

Enquire Now

Start learning today!

Click Hereto customize your Training

Objectives

  • Optimizing Search
  • Report Acceleration
  • Data Model Acceleration
  • Using the tstats Command

Content

Topic 1 – Optimizing Search

  • Understand how search modes affect performance
  • Examine the role of the Splunk Search Scheduler
  • Review general search practices

Topic 2 – Report Acceleration

  • Define acceleration and acceleration types
  • Understand report acceleration and create an accelerated report
  • Reveal when and how report acceleration summaries are created
  • Search against acceleration summaries

Topic 3 – Data Model Acceleration

  • Understand data model acceleration
  • Accelerate a data model
  • Use the datamodel command to search data models

Topic 4 – Using the tstats Command

  • Explore the tstats command
  • Search acceleration summaries with tstats
  • Search data models with tstats
  • Compare tstats and stats

Audience

  • Splunk Administrator
  • Developer
  • User
  • Knowledge Manager
  • Architect

Prerequisites

To be successful, students should have completed the following prerequisite courses:

  • Search Under the Hood
  • Multivalue Fields
  • Scheduling Reports & Alerts
  • Data Models

Certification

product-certification

Course Benefits

product-benefits
  • Career growth
  • Broad Career opportunities
  • Worldwide recognition from leaders
  • Up-to Date technical skills
  • Popular Certification Badges

Splunk Popular Courses

splk-dyd

This course focuses on creating inputs, chain searches, event annotations, and improving dashboard performance.

splk-introdyd

This course focuses on dashboard creation, including prototyping, the dashboard definition, layouts types, adding visualizations, and dynamic coloring.

splk-lls

This course will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources

splk-wtime

This course will focus on searching and formatting time in addition to using time commands and working with time zones.
Enquire Now
 
 
 
 
ZmhSy7
By clicking "Submit", I agree to the Terms Of Use and Privacy Policy