0. Splunk 的安装
可以从下面地址来下载 Splunk,版本是 6.2.2
https://www.splunk.com/page/previous_releases
splunk tutorial:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial
比较建议在你自己的 PC 上面安装 Splunk。
安装好之后,会提示你需要更换用户名
source="census.csv" host="DESKTOP-K1NJT4U" sourcetype="csv"
STNAME = "Texas"
STNAME = "Califonia" OR STNAME = "Texas"
source="census.csv" host="DESKTOP-K1NJT4U" sourcetype="csv" STNAME = "Texas" | table CTYNAME
CENSUS2010POP > 10000 | sort CENSUS2010POP desc | table CENSUS2010POP, STNAME CENSUS2010POP > 10000 | sort -CENSUS2010POP | table CENSUS2010POP, STNAME
| stats count
| stats sum(CENSUS2010POP) | stats mean(CENSUS2010POP)