Splunk is innovative technology and a comprehensive business intelligence tool used to query and visualize enterprise data.  Users can search machine data across an enterprise where the data is located in various repositories, in different formats, and available via various sources.  Splunk makes searching, examination, collating, and reporting on disparate data flexible and possible.  Students will leave class with the ability to leverage Splunk in their workplace and interpret machine data in their domain.

Splunk provides a single syntax and user interface for accessing a variety of data. In class, students will learn the essentials of this syntax to create simple and complex search results and reports.  User will also learn how to navigate the Splunk user experience.

Every module starts with an upfront exercise and then a series of walkthroughs designed to reinforce important concepts and skills. At the end of the course, you are prepared to create real world solutions using Splunk from the knowledge gained from this training.

Course Duration: 2 days
Course Outline:
  • Day One
    • Introduce Splunk
    • Identify the contents of search results
    • Control a search job
    • Set the time range of a search
    • Export search results
    • Save and share search results
    • Schedule searches
    • Understand fields
    • Use the fields sidebar

 

  • Day Two
    • Create tags and use tags in a search
    • Create and use event types in a search
    • Create an alert
    • View fired alerts
    • Create reports and charts
    • Create dashboards and add reports
    • Understand search language syntax concepts
    • Understand the stats command