# Tags #splunk #certifications #splunk-queries # Helpful Docs - [Tutorialspoint.com](https://www.tutorialspoint.com/splunk/splunk_source_types.htm) # Notes ##### Sequence of Search-Time Operations - 1 - Inline field extraction - 2 - Field extraction that uses a field transform - 3 - Automatic key-value field extraction - 4 - Field aliasing - 5 - Calculated fields - 6 - Lookups - 7 - Event types - 8 - Tags ##### Splunk Knowledge Categories - Data interpretation - fields and extractions - Data classification - event types and transactions - Data enrichment - lookups and workflow actions - Data normalization - tags and aliases - Data model ##### Splunk Chart Types - Column chart and bar chart - Represent one or more dimensions in a results set, these charts plot data on two axes, each axis represents a results field - Column and bar charts can compare values and fields - Line chart and area chart - Line charts can show value changes over time - Area charts show changes in an aggregated value over time - Pie chart - Shows a single dimension, pie slice size represents the density or frequency of values in a field - Scatter chart and bubble chart - Represent multiple dimensions in a results set, these charts plot data on two axes, data point appearance, size, and/or distribution show additional patterns or relationships ##### Data Model Acceleration - Two types of Data Model Acceleration - Ad Hoc - Applies to a single dataset - Is run over all time - Exists for the duration of a user's pivot session - Persistent - Turned on my an admin - Happens in the background - Can be scoped to shorter time ranges - Is used any time a search is run against a dataset in an acceleration-enabled data model - HPAS - High performance analytics store