Skip to content
fernet.consultores

Splunk Cloud

SPL Development.

Searches, macros, lookups and alerts in SPL written to be correct, fast and maintainable.

The problem we solve.

A badly written search consumes resources shared by everyone, takes minutes to respond, or returns incomplete results without warning. And when only one person understands the critical SPL, the platform depends on them.

What’s included.

  • Development of searches, reports and alerts
  • Reusable macros, lookups and knowledge objects
  • Rewriting of slow searches
  • Review of existing SPL
  • Documentation and style conventions

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We write or rewrite searches, macros and lookups following a common style guide.

We compare results and run times with the previous version to demonstrate that the new search is correct and more efficient.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • SPL and SPL2
  • tstats and data models
  • Macros and lookups
  • KV Store
  • Summary indexing
  • Report acceleration

The same question, a different speed.

Which web servers return the most errors? A search over raw events versus the same question over an accelerated data model. Switch between the two and compare what Splunk has to read.

```Scans every index and reads each raw event```
index=* sourcetype=access_combined status>=500
| stats count by host
| sort - count
What it readsRaw events
Scales withEverything indexed
Relative work

Qualitative comparison. The actual improvement depends on volume, retention and whether the data model is accelerated and up to date.

Use cases.

Business alerts

Turn a business question into a reliable search.

Slow searches

Rewrite the queries that consume the most resources.

Legacy content

Tidy up and document SPL nobody dares touch.

Benefits for your organisation.

  • Faster responses
  • Less load on the platform
  • Correct, verifiable results
  • Knowledge shared across the team

Deliverables.

  • Developed searches and alerts
  • Library of macros and lookups
  • Optimisation report
  • SPL style guide

Frequently asked questions.

Can you review the SPL we already have?

Yes. We prioritise by resource consumption and criticality, and return each search with its optimised version.

Do you use SPL2?

When the product supports it and it adds value. On Splunk Cloud, most content is still in classic SPL.

Do you train our team along the way?

If you need it, every deliverable includes an explanation of the decisions taken.

Shall we talk about SPL Development?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service