Splunk

Course Overview

Splunk is a software platform that is used for searching, analyzing, and visualizing machine-generated data. It is commonly used in a variety of industries, including IT, cybersecurity, and business analytics. Splunk Training is a course that teaches participants how to use Splunk to collect, index, and analyze data. The training covers topics such as how to search and navigate data, how to create and share reports and dashboards, and how to use Splunk to troubleshoot problems. Upon completing the training, participants will have the skills and knowledge needed to use Splunk effectively in their organization.

At the end of the training, participants will be able to:

  1.  Appreciate the challenges of working with machine data
  2. Install and setup Splunk for first use
  3. Explain the major components of Splunk
  4. Create and manage user roles
  5. Use commands for basic search, time range search and transforming data
  6. Interpret knowledge objects to define searches, lookups, and tags
  7. Setup alerts, visualizations and dashboards
  8. Create Splunk clusters and indexed search heads

Pre-requisite

Understanding of analytics is good to have.

Duration

2 days

Course Outline

  1. What is Machine Data & its challenges?
  2. Need for Splunk and its features
  3. Splunk Products and their Use-Case
  4. Download and Install Splunk
  5. Splunk Components: Search Head, Indexer, Forwarder, Deployment Server, & License Master
  6. Splunk Architecture
  7. Splunk Licensing options
  1. Introduction to Authentication techniques
  2. User Creation and Management
  3. Splunk Admin Role & Responsibilities
  4. Indexes
  5. Data Ageing
  6. Introduction to Splunk configuration files
  1. Data onboarding via flat files
  2. Data onboarding via UF (Universal Forwarder)
  3. Basic search commands in Splunk – Fields, Table, Sort, Rename, Search
  4. Time ranges while searching
  5. Reporting & Transforming commands in Splunk: – Top, Rare, Stats, Chart, Timechart, Dedup, Rex
  1. Splunk Knowledge
  2. Categories of Splunk Knowledge
  3. Fields
  4. Field extraction
  5. Event types
  6. Transactions
  7. Defining a lookup
  8. Configuring an automatic lookup
  9. Using the lookup in searches and reports
  10. Workflow action
  11. Tags
  12. Creating and managing tags
  13. Defining and searching field aliases
  14. Overview of Data Model
  1. Create Alerts triggered on certain conditions
  2. Different Splunk Visualizations
  3. Create Reports with search results
  4. Create Dashboards with different Charts and other visualizations
  5. Set permissions for Reports and Dashboard
  6. Create Reports and schedule them using cron schedule
  7. Share Dashboard with other teams
  1. Install Splunk on Linux OS
  2. Use the frequently used Splunk CLI commands
  3. Learn the best practices while setting up a Clustering environment
  4. Splunk Clustering
  5. Implement Search Head Clustering
  6. Implement Indexer Clustering
  7. Deploy an App on the Search Head cluster

Reviews