# Tags
#splunk
#certifications
#splunk-queries
# Helpful Docs
- [Tutorialspoint.com](https://www.tutorialspoint.com/splunk/splunk_source_types.htm)
# Notes
##### Sequence of Search-Time Operations
- 1 - Inline field extraction
- 2 - Field extraction that uses a field transform
- 3 - Automatic key-value field extraction
- 4 - Field aliasing
- 5 - Calculated fields
- 6 - Lookups
- 7 - Event types
- 8 - Tags
##### Splunk Knowledge Categories
- Data interpretation - fields and extractions
- Data classification - event types and transactions
- Data enrichment - lookups and workflow actions
- Data normalization - tags and aliases
- Data model
##### Splunk Chart Types
- Column chart and bar chart
- Represent one or more dimensions in a results set, these charts plot data on two axes, each axis represents a results field
- Column and bar charts can compare values and fields
- Line chart and area chart
- Line charts can show value changes over time
- Area charts show changes in an aggregated value over time
- Pie chart
- Shows a single dimension, pie slice size represents the density or frequency of values in a field
- Scatter chart and bubble chart
- Represent multiple dimensions in a results set, these charts plot data on two axes, data point appearance, size, and/or distribution show additional patterns or relationships
##### Data Model Acceleration
- Two types of Data Model Acceleration
- Ad Hoc
- Applies to a single dataset
- Is run over all time
- Exists for the duration of a user's pivot session
- Persistent
- Turned on my an admin
- Happens in the background
- Can be scoped to shorter time ranges
- Is used any time a search is run against a dataset in an acceleration-enabled data model
- HPAS
- High performance analytics store