Splunk is an innovative, comprehensive business intelligence tool used to query and visualize enterprise data.  Users can search machine data across an enterprise where the data is located in various repositories, different formats and is available via various sources. Splunk makes searching, examination, collating and reporting on disparate data flexible and possible. Students will leave class with the ability to leverage Splunk in their workplace and interpret machine data in their domain.

Splunk provides a single syntax and user interface for accessing a variety of data. In this class, students will learn the essentials of syntax, create search results of varying complexity and generate reports. Several typical and advanced commands are introduced, and upon completion of the course, participants will know how to confidently navigate the Splunk user interface.

Installing, configuring and administering Splunk can be challenging, so this course provides the necessary tools to deftly setup and manage Splunk for clients. The students will receive a “cheat sheet” during class. This sheet is a comprehensive and an invaluable guide, especially for someone new to Splunk.

Every class module starts with an upfront exercise followed by a series of walkthroughs designed to reinforce important concepts and skills. At the end of the course, students are prepared to create real-world solutions using Splunk from the knowledge gained from this training.

Course Duration: 4 days
Course Outline:
  • Day One
    • Introduce Splunk
    • Identify The Contents of Search Results
    • Control a Search Job
    • Set The Time Range of a Search
    • Export Search Results
    • Save and Share Search Results
    • Schedule Searches
    • Understand Fields
    • Use The Fields Sidebar

 

  • Day Two
    • Create Tags and Use Tags in a Search
    • Create and Use Event Types in a Search
    • Create an Alert
    • View Fired Alerts
    • Create Reports and Charts
    • Create Dashboards and Add Reports
    • Understand Search Language Syntax Concepts
    • Understand The Stats Command
    • Review Splunk Terminology
    • Review Splunk Cheat Sheet

 

  • Day Three
    • Installing Splunk
    • Different Ways in Configure Splunk
    • Splunk Configuration Files
    • Splunk Api
    • Configuration Bundlestop
    • Stats
    • Addcoltotals
    • Addtotals
    • Overview of Transactions
    • Search Transactions

 

  • Day Four
    • Universal Forwarder
    • Forwarder Management
    • Understanding Monitor Inputs
    • What are Network Inputs
    • Concept of Indexing in Splunk
    • Data Preview and Parsing Phase
    • Raw Data Manipulation
    • Extraction of Fields
    • Performing Distributed Search