Vendors

Overview

This 18-hour Instructor led course is for administrators new to Splunk Cloud and those wanting to become more experienced in managing Splunk Cloud instances.

The course provides administrators with the opportunity to gain the skills, knowledge and best practices for data management and system configuration for data collection and ingestion required in a Splunk Cloud environment to create a productive Splunk SaaS deployment. The hands-on labs provide the opportunity to learn and ask questions on how to manage and maintain the platform, the users and how to effectively get data into Splunk Cloud. Modules include data inputs and forwarder configuration, data management, user accounts, and basic monitoring and problem isolation.

img-course-overview.jpg

What You'll Learn

  • Splunk Cloud overview
  • Managing user authentication and authorization in Splunk
  • Managing Splunk indexes
  • Using Splunk configuration files
  • Configuring and managing Splunk forwarders
  • Configuring inputs to Cloud, including files and directories from forwarders, API, Scripted, HEC and Application based inputs
  • Exploring the parsing phase and data preview
  • Manipulating raw data
  • Installing and managing applications
  • Problem isolation and working with Splunk Cloud support

Who Should Attend

  • Splunk Administrator
  • Developer
  • User
  • Knowledge Manager
  • Architect
img-who-should-learn.png

Prerequisites

To be successful, students should have a working knowledge of the topics covered in the following courses:

  • What is Splunk?
  • Intro to Splunk
  • Using Fields
  • Introduction to Knowledge Objects
  • Creating Knowledge Objects
  • Creating Field Extractions

Learning Journey

Coming Soon...

Module 1 – Splunk Cloud Overview

  • Describe Splunk and Splunk Cloud features and topology
  • Identify Splunk Cloud administrator tasks
  • Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience
  • Secure Splunk deployments best practices
  • Explain Splunk Cloud data ingestion strategies

Module 2 – Managing Users

  • Identify Splunk Cloud authentication options
  • Add Splunk users using native authentication
  • Create a custom role
  • Integrate Splunk with LDAP, Active Directory or SAML
  • Use Workload Management to manage user resource usage
  • Manage users in Splunk

Module 3 – Managing Indexes

  • Understand cloud indexing strategy
  • Define and create indexes
  • Manage data retention and archiving
  • Delete and mask data from an index
  • Monitor indexing activities

Module 4 – Using Configuration Files

  • Describe Splunk configuration directory structure
  • Describe the configuration layering process with index and search time precedence
  • Use Splunk tools to examine configuration settings such as btool

Module 5 – Managing Apps

  • Review the process for installing apps
  • Define the purpose of private apps
  • Upload private apps
  • Describe how apps are managed

Module 6 – Configuring Forwarders

  • List Splunk forwarder types
  • Understand the role of forwarders
  • Configure a forwarder to send data to Splunk Cloud
  • Test the forwarder connection
  • Describe optional forwarder settings

Module 7 – Managing Forwarders

  • Describe Splunk Deployment Server (DS)
  • Manage forwarders using deployment apps
  • Configure deployment clients and client groups
  • Monitor forwarder management activities

Module 8 – Forwarder Inputs

  • Describe the Splunk process for inputting data
  • Create file and directory monitor inputs
  • Use optional settings for monitor inputs
  • Creating network inputs

Module 9 – Common Inputs

  • Create REST API inputs
  • Create a basic scripted input
  • Identify Linux-specific inputs
  • Identify Windows-specific inputs
  • Create Splunk HTTP Event Collector (HEC) agentless inputs

Module 10 – Additional Inputs

  • Understand how inputs are managed using apps or add-ons
  • Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub

Module 11 – Fine-tuning Inputs

  • Describe the default processing that occurs during the input phase
  • Configure input phase options, such as source type fine-tuning and character set encoding
  • Reset file check pointers on a forwarder using the btprobe command

Module 12 – Parsing Phase and Data Preview

  • Describe the default processing that occurs during parsing
  • Optimize and configure event line breaking
  • Modify how timestamps and time zones are extracted or assigned to events
  • Use Data Preview to validate event creation during the parsing phase

Module 13 – Manipulating Input Data

  • Explore Splunk transformation methods
  • Mask, filter and route data with SEDCMD and TRANSFORMS
  • Override sourcetype or host based upon event values
  • Create and manage rulesets with Ingest Actions
  • Mask, filter and route data with Ingest Action rules

Module 14 – Managing Splunk Cloud

  • Secure ingest with Splunk Cloud Private Connectivity with AWS
  • Describe Federated Search functionality
  • Describe Splunk connected experience apps such as Splunk Secure Gateway
  • Monitor and manage resource utilization by business units and users using Splunk App for Chargeback
  • Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service

Module 15 – Supporting Splunk Cloud

  • Know how to isolate problems before contacting Splunk Cloud Support
  • Use Isolation Troubleshooting
  • Define the process for engaging Splunk Support

Appendix

  • Explore Splunk security fundamentals

Frequently Asked Questions (FAQs)

  • Why get Splunk certified?

    Splunk certifications validate your expertise in data analytics and your proficiency in using the Splunk platform.

    These certifications demonstrate your ability to leverage Splunk's powerful tools for data collection, analysis, and visualization, making you a valuable asset to organizations seeking to gain actionable insights from their data.

    Splunk-certified professionals are in high demand across various industries, including IT, security, and business analytics.

  • What to expect for the examination?

    Splunk offers a variety of certification exams at different levels, covering various domains and products within the Splunk platform.

    Exams typically consist of multiple-choice and scenario-based questions that assess your knowledge and skills in using Splunk to solve real-world problems.

    Note: Certification requirements and policies may be updated by Splunk from time to time. We apologize for any discrepancies; do get in touch with us if you have any questions.

  • How long is Splunk certification valid for?

    All Splunk certifications are valid for three years from the date of passing the highest-level certification exam.

    To maintain your certification, you will need to recertify before it expires. You have three options for recertification:

    - Pursue a higher-level certification (including any required prerequisite courses), in which case your lower-level certifications would also be renewed on the date of passing the next-level certification exam.

    - Retake a certification exam within the final year of their recertification window to renew their certifications at that level (and any applicable downstream certifications).

    - Complete continuing education courses at any point in the three year recertification window beginning the date of badge issuance.

    Note: Certification requirements and policies may be updated by Splunk from time to time. We apologize for any discrepancies; do get in touch with us if you have any questions.

  • Why take this course with Trainocate?

    Here’s what sets us apart:

    - Global Reach, Localized Accessibility: Benefit from our geographically diverse training hubs in 16 countries (and counting!).

    - Top-Rated Instructors: Our team of subject matter experts (with high average CSAT and MTM scores) are passionate to help you accelerate your digital transformation.

    - Customized Training Solutions: Choose from on-site, virtual classrooms, or self-paced learning to fit your organization and individual needs.

    - Experiential Learning: Dive into interactive training with our curated lesson plans. Participate in hands-on labs, solve real-world challenges, and take on comprehensive assessments.

    - Learn From The Best: With 30+ authorized training partnerships and countless awards from Microsoft, AWS, Google – you're guaranteed learning from the industry's elite.

    - Your Bridge To Success: We provide up-to-date course materials, helpful exam guides, and dedicated support to validate your expertise and elevate your career.

Keep Exploring

Course Curriculum

Training Schedule

Exam & Certification

Frequently Asked Questions

img-improve-career.jpg

Improve yourself and your career by taking this course.

More Courses By Splunk

img-get-info.jpg

Ready to Take Your Business from Great to Awesome?

Level-up by partnering with Trainocate. Get in touch today.

Name
Email
Phone
I'm inquiring for
Inquiry Details

By providing your contact details, you agree to our Privacy Policy.