1. Splunk Fundamentals
- Introduction to Splunk and its architecture
- Understanding core components
- Installing and setting up Splunk
- Getting data into Splunk (data onboarding)
2. Searching and Working with Data
- Basic searching techniques
- Using fields and search language
- Transforming commands and time-based commands
- Filtering results and manipulating data
3. Dashboards, Reports, and Alerts
- Creating reports and dashboards
- Scheduled reports and alerts
- Trendlines, mapping, and single-value visualisations
- Dashboard customisation, drilldowns, and advanced behaviours
4. Knowledge Objects
- Creating and managing fields
- Field aliases and calculated fields
- Tags, event types, and macros
- Using lookups
- Creating data models and using the Common Information Model (CIM)
5. Splunk Administration Basics
- Overview of Splunk deployment
- Understanding Splunk configuration files
- Introduction to Splunk Apps
- Indexes and index management
- Splunk user management
- Forwarder types (universal vs heavy) and configuration
- Monitor inputs, network and scripted inputs, Windows and agentless inputs
- Parsing phase and data preview
- Supporting knowledge objects
- Basic forwarding configuration
- Introduction to distributed search and using splunk diag
Write a public review