Advanced SPL, Windowing & Production Recipes
Advanced Splunk SPL — regex extraction (rex), JSON parsing (spath), windowing (eventstats vs streamstats), transaction vs stats, subsearch optimization, and production SRE observability queries.
Advanced Splunk SPL — regex extraction (rex), JSON parsing (spath), windowing (eventstats vs streamstats), transaction vs stats, subsearch optimization, and production SRE observability queries.
Physical mechanisms of long-running transaction failures: Undo tablespace and History List Length (HLL) bloat, the single-threaded rollback trap, the critical difference between KILL QUERY and KILL CONNECTION, and the Metadata Lock (MDL) queue cascade exhausting connection pools.
Load balancing algorithms, health checks, failover strategies, chaos engineering, disaster recovery, and SRE practices for building reliable distributed services.
Online Schema Change mechanics in MySQL and PostgreSQL: why staging finishes in 40s while production exhausts connection pools, ALGORITHM & LOCK matrix, innodb_online_alter_log_max_size overflow, gh-ost vs pt-osc, and PostgreSQL's INVALID index trap.
PostgreSQL Write-Ahead Logging and replication mechanics: why a no-op UPDATE generates 380MB of WAL, replication lag causes, orphan replication slots exhausting disk, silent archive_command failures, and the 2 AM 95% disk emergency playbook.
Post-mortem analysis of production OutOfMemoryError failures: why an innocent token-masking regex crashed a Kubernetes pod, 4 JVM memory leak avenues, metrics senses, and the 2 AM incident triage playbook.