官术网_书友最值得收藏!

Viewing the Destinations app

Next we will see our Destinations app in action! Remember that we have configured it to draw events from a prototype web company. That is what we did when we set it up to work with Eventgen. Now, let's look at some of our data:

  1. After a successful restart, log back in to Splunk and proceed to your new Destinations app:
  1. In the Search field, type this search query and select Enter:
SPL> index=main

Examine the event data that your new app is enabling to come into Splunk. You will see a lot of references to browsers, systems, and so forth, the kinds of information that make a web-based e-commerce company run.

Try changing the time range to Real-time (5 minute window) to see the data flow in before your eyes:

Congratulations! You now have real-time web log data that we can use in subsequent chapters.

Tip from the Fez: Running a Splunk report under a real-time window places heavier strain on Splunk because it is rerunning the search over and over to generate the live nature of the real-time window. Unless absolutely needed, choose to have reports run for a set time period on user demand or a previously assigned schedule.
主站蜘蛛池模板: 安泽县| 灌云县| 唐海县| 东兰县| 班玛县| 和龙市| 乳山市| 马关县| 浦城县| 青河县| 阿尔山市| 阳东县| 石河子市| 沙田区| 马公市| 孝昌县| 梧州市| 吴川市| 广水市| 漳平市| 宁阳县| 利辛县| 兰西县| 赣榆县| 沙湾县| 叙永县| 铅山县| 无棣县| 双辽市| 犍为县| 开原市| 库尔勒市| 南溪县| 克东县| 山阳县| 达孜县| 嘉禾县| 东山县| 察隅县| 星子县| 察哈|