Result Modification

Course code: SPLUNKRESM

This three-hour course is for power users who want to use commands to manipulate output and normalize data. Topics will focus on specific commands for manipulating fields and field values, modifying result sets, and managing missing data. Additionally, students will learn how to use specific eval command functions  to normalize fields and field values across multiple data sources.

535 EUR

647 EUR including VAT

The earliest date from 07.05.2024

Selection of dates
onas
Do you have a question?
+420 731 175 867 edu@edutrainings.cz

Professional
and certified lecturers

Internationally
recognized certifications

Wide range of technical
and soft skills courses

Great customer
service

Making courses
exactly to measure your needs

Course dates

Starting date: 07.05.2024

Type: Virtual

Course duration: 3 hours

Language: en

Price without VAT: 535 EUR

Register

Starting date: Upon request

Type: In-person/Virtual

Course duration: 3 hours

Language: en

Price without VAT: 535 EUR

Register

Starting
date
Place
Type Course
duration
Language Price without VAT
07.05.2024 Virtual 3 hours en 535 EUR Register
Upon request In-person/Virtual 3 hours en 535 EUR Register
G Guaranteed course

Didn't find a suitable date?

Write to us about listing an alternative tailor-made date.

Contact

Course structure

Module 1 – Manipulating Output

  • Convert a 2-D table into a flat table with the untable command
  • Convert a flat table into a 2-D table with the xyseries command

Module 2 – Modifying Result Sets

  • Append data to search results with the appendpipe command
  • Calculate event statistics with the eventstats command
  • Calculate “streaming” statistics with the streamstats command
  • Modify values to segregate events with the bin command

Module 3 – Managing Missing Data

  • Find missing and null values with the fillnull command

Module 4 – Modifying Field Values

  • Understand the eval command
  • Use conversion and text eval functions to modify field values
  • Reformat fields with the foreach command

Module 5 – Normalizing with eval

  • Normalize data with eval functions
  • Identify eval functions to use for data and field normalization

Prerequisites

To be successful, students should have a solid understanding of the
following:

  • How Splunk works
  • Creating search queries
  • Knowledge objects

Do you need advice or a tailor-made course?

onas

product support

ComGate payment gateway MasterCard Logo Visa logo