top of page
top

Leveraging Lookups and Subsearches

Leveraging Lookups and Subsearches

Leveraging Lookups and Subsearches

authorized-learning-partner.png

Price
Duration

On Request

1 Day

Courses
PDF Outline
PDF Outline

Prerequisites

Prerequisits

To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:
• Intro to Splunk
• Using Fields
• Visualizations
• Working with Time

• Statistical Processing
• Comparing Values
• Result Modification
• Scheduling Reports and Alerts
• Introduction to Dashboards

What you'll will learn

What you’ll learn in this course

This course is designed for Splunk users, analysts, and administrators who want to enhance their searches with lookups and subsearches.

You will learn how to use lookups to enrich your data and how to write subsearches to correlate and filter data from multiple sources.

Objectives

Course Objectives

Course Outline

Outlines
PDF Outline

Module 1 – Using Lookup Commands
• Understand lookups
• Use the inputlookup command to search lookup files
• Use the lookup command to invoke field value lookups
• Use the outputlookup command to create lookups
• Invoke geospatial lookups in search

Module 2 – Adding a Subsearch
• Define subsearch
• Use subsearch to filter results
• Identify when to use subsearch
• Understand subsearch limitations and alternatives
Module 3 – Using the return Command
• Use the return command to pass values from a subsearch
• Compare the return and fields commands

reg1

Further information

If you would like to know more about this course please contact us

Schedule
authorized-learning-partner.png
For dates in South Africa and Africa region 

Thanks for registering. our team will contact you soon !

Registration

ILT/VILT
bottom of page