Splunk 7.2 Fast Start Course Overview

This certification track prepares Splunk Partners and Customers to become Splunk Certified Admins. This path includes the Splunk Certified Power User program, which is a prerequisite to becoming a Splunk Certified Admin.

 

This is a Rare Course and it can be take up to 3 weeks to arrange the training.

  • 1. Do you have limited Window for training?
  • 2. Can you only spend 4-hours per day?
  • 3. Do you want to start training immediately?
  • If your answer is yes to any one of the above, you need 1-on-1- Training
The 1-on-1 Advantage
Methodology
Flexible Dates
4-Hour Sessions
  • View video
  • The course will be free if we are not able to start within 7 days of booking.
  • Only applicable for courses on which this logo appears.

Your will learn:

Module 1 – Introduction
  • Overview of Buttercup Games Inc.
  • Lab environment
  • Search fundamentals review
  • Case sensitivity
  • Using the job inspector to view search performance
  • Explore data structure requirements
  • Explore visualization types
  • Create and format charts and timecharts
  • The iplocation command
  • The geostats command
  • The geom command
  • The addtotals command
  • The eval command
  • Using the search and where commands to filter results
  • The filnull command
  • Identify transactions
  • Group events using fields
  • Group events using fields and time
  • Search with transactions
  • Report on transactions
  • Determine when to use transactions vs. stats
  • Identify naming conventions
  • Review permissions
  • Manage knowledge objects
  • Perform regex field extractions using the Field Extractor (FX)
  • Perform delimiter field extractions using the FX
  • Describe, create, and use field aliases
  • Describe, create and use calculated fields
  • Create and use tags
  • Describe event types and their uses
  • Create an event type
  • Describe macros
  • Create and use a basic macro
  • Define arguments and variables for a macro
  • Add and use arguments with a macro
  • Describe the function of GET, POST, and Search workflow actions
  • Create a GET workflow action
  • Create a POST workflow action
  • Create a Search workflow action
  • Describe the relationship between data models and pivot
  • Identify data model attributes
  • Create a data model
  • Use a data model in pivot
  • Describe the Splunk CIM
  • List the knowledge objects included with the Splunk CIM Add-On
  • Use the CIM Add-On to normalize data
  • Splunk overview
  • Identify Splunk components
  • Identify Splunk system administrator role
  • Identify Splunk installation steps
  • Use Splunk CLI
  • Use Splunk CLI
  • Identify license types
  • Describe license violations
  • Add and remove licenses
  • Describe Splunk apps and add-ons
  • Install an app on a Splunk instance
  • Manage app accessibility and permissions
  • Describe Splunk configuration directory structure
  • Understand configuration layering process
  • Use btool to examine configuration settings
  • Understand how indexes function
  • Understand the types of index buckets
  • Create new indexe
  • Explain the advantages of using multiple indexes
  • Monitor indexes with Monitoring Console
  • Manage indexes with Splunk web
  • Describe indexes.conf attributes and stanzas
  • Customize index retention policies
  • Delete events from an index
  • Restore frozen buckets
  • Add Splunk users using native authentication
  • Describe user roles in Splunk
  • Create a custom role
  • Splunk authentication options
  • Identify forwarder configuration steps
  • List Splunk forwarder types
  • Configure the forwarder
  • Identify forwarder configuration files
  • Describe how distributed search works
  • Explain the roles of the search head and search peers
  • Configure a distributed search group
  • List search head scaling options
  • Splunk overview
  • Identify Splunk data administrator role
  • List the four phases of Splunk Index
  • List Splunk input options
  • Describe the band settings for an input
  • Understand the role of production Indexers and Forwarders
  • Understand the functionality of Universal Forwarders and Heavy Forwarders
  • Configure Forwarders
  • Identify additional Forwarder options
  • Explain the use of Forwarder Management
  • Describe Splunk Deployment Server
  • Manage forwarders using deployment apps
  • Configure deployment clients
  • Configure client groups
  • Monitor forwarder management activities
  • Create file and directory monitor inputs
  • Use optional settings for monitor inputs
  • Deploy a remote monitor input
  • Create network (TCP and UDP) inputs
  • Describe optional settings for network inputs
  • Create a basic scripted input
  • Identify Windows input types and uses
  • Understand additional options to get data into Splunk
  • Understand the default processing that occurs during input phase
  • Configure input phase options, such as sourcetype fine- tuning and character set encoding
  • Understand the default processing that occurs during parsing
  • Optimize and configure event line breaking
  • Explain how timestamps and time zones are extracted or assigned to events
  • Use Data Preview to validate event creation during the parsing phase
  • Explain how data transformations are defined and invoked
  • Use transformations with props.conf and transforms.conf to:
  • Use SEDCMD to modify raw data
  • Create field extractions
  • Configure collections for KV Store
  • Manage Knowledge Object permissions
  • Control automatic field extraction
  • Identify Splunk diag
  • Using Splunk diag
Live Online Training (Duration : 40 Hours) Fee On Request
Group Training
06 - 10 Jun 09:00 AM - 05:00 PM CST
(8 Hours/Day)
04 - 08 Jul 09:00 AM - 05:00 PM CST
(8 Hours/Day)
1-on-1 Training
4 Hours
8 Hours
Week Days
Weekend

Start Time : At any time

12 AM
12 PM

1-On-1 Training is Guaranteed to Run (GTR)
Classroom Training (Available: London, Dubai, India, Sydney, Vancouver)
Duration : On Request
Fee : On Request
On Request
Classroom Training is available. Enquire for the fee Click
Ultra-Fast Track

If you can't spare 40 hours. We can offer you an Ultra-Fast Track for 20 hours

Course Prerequisites
  • Basic Computer Knowledge.

Request More Information

Add Name and Email Address of participant (If different from you)

FAQ's


The Fee includes:
  • Courseware
  • Remote Labs
Yes, Koenig Solutions is a Splunk Learning Partner