SPLK-ENTCADM8.2 - Splunk 9.0 Cluster Administration

This 3-virtual day certification & training course is for an experienced Splunk Enterprise administrator who is new to Splunk Clusters. The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment. It covers installation, configuration, management, and monitoring of Splunk clusters. While Splunk Clusters are supported in Windows environments, the class lab environment is running Linux instances only.

Duration: 3.0 days

Enquire Now

Start learning today!

Click Hereto customize your Training


  • Large-scale Splunk Deployment Overview
  • Single-site Indexer Cluster
  • Indexer Cluster Management and Administration
  • Forwarder Configuration
  • Search Head Cluster
  • Search Head Cluster Management and Administration
  • KV Store Collection and Lookup Management
  • SmartStore Implementation Overview


Module 1 - Large-scale Splunk Deployment Overview

  • Factors that affecting deployment design
  • How Splunk Enterprise can scale
  • Splunk License Master

Module 2 - Single-site Indexer Cluster

  • How Splunk single-site indexer clusters work
  • Indexer cluster components and terms
  • Splunk single-site indexer cluster configuration
  • Splunk indexer cluster log channels

Module 3 - Multisite Indexer Cluster

  • How Splunk multisite indexer clusters work
  • Multisite indexer cluster terms
  • Multisite indexer cluster configuration
  • Optional multisite indexer cluster configurations

Module 4 - Indexer Cluster Management and Administration

  • Peer offline and decommission
  • Master app bundles
  • Indexer cluster storage utilization options
  • Site mapping
  • Monitoring Console for indexer cluster environment

Module 5 - Forwarder Management

  • Indexer discovery
  • Optional indexer discovery configurations
  • Volume-based forwarder load balancing

Module 6 - Search Head Cluster

  • Splunk search head cluster overview
  • Search head cluster configuration

Module 7 - Search Head Cluster Management and Administration

  • Search head cluster deployer
  • Captaincy transfer
  • Search head member addition and decommissioning
  • Monitoring Console for Search Head Cluster

Module 8 - KV Store Collection and Lookup Management

  • KV Store collection in Splunk clusters
  • KV Store monitoring with Monitoring Console

Module 9 - SmartStore Implementation

  • SmartStore architecture overview
  • Deploy and manage SmartStore




To be successful, students should have a solid understanding of the following courses:

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2

OR the following single-subject courses:

  • What Is Splunk?
  • Intro to Splunk
  • Using Fields
  • Scheduling Reports and Alerts
  • Visualizations
  • Leveraging Lookups and Subsearches
  • Search Under the Hood
  • Introduction to Knowledge Objects
  • Creating Knowledge Objects
  • Enriching Data with Lookups
  • Data Models
  • Introduction to Dashboards

Students should also have completed the following courses:

  • Splunk System Administration
  • Splunk Data Administration
  • Troubleshooting Splunk Enterprise



Course Benefits

  • Career growth
  • Broad Career opportunities
  • Worldwide recognition from leaders
  • Up-to Date technical skills
  • Popular Certification Badges

Splunk Popular Courses


This course focuses on creating inputs, chain searches, event annotations, and improving dashboard performance.


This course focuses on dashboard creation, including prototyping, the dashboard definition, layouts types, adding visualizations, and dynamic coloring.


This course will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources


This course will focus on searching and formatting time in addition to using time commands and working with time zones.
Enquire Now
By clicking "Submit", I agree to the Terms Of Use and Privacy Policy