Architecting Splunk 8.0.1 Enterprise Deployments
Upcoming Classes
Online
Instructor-led online training
Location | May 2022 | Jun 2022 | Jul 2022 | Aug 2022 | Sep 2022 | Oct 2022 | Nov 2022 |
---|---|---|---|---|---|---|---|
APAC Sydney - Virtual |
May 30 – May 31 | ||||||
AMER Pacific Time - Virtual |
Jun 2 – Jun 3 Jun 23 – Jun 24 |
Jul 11 – Jul 12 Jul 25 – Jul 26 | |||||
EMEA UK Time - Virtual |
Jun 13 – Jun 14 Jun 27 – Jun 28 |
Jul 7 – Jul 8 Jul 18 – Jul 19 | |||||
AMER Eastern Time - Virtual |
Jun 13 – Jun 14 Jun 27 – Jun 28 |
Jul 11 – Jul 12 Jul 25 – Jul 26 | |||||
APAC Singapore - Virtual |
Jun 20 – Jun 21 |
Jul 11 – Jul 12 |

Summary
This nine-hour course focuses on large enterprise deployments. Students will learn steps and best practices for planning, data collection and sizing for a distributed deployment. Workshop-style labs challenge students to make design decisions about an example enterprise deployment.
Description
- Requirements definition
- Index and resource planning
- Clustering Overview
- Forwarder and Deployment
- Integration
- Performance Monitoring and Tuning
- Use Cases
Objectives
Module 1 – Introduction
- Overview of the Splunk deployment planning process and associated tools
Module 2 – Project Requirements
- Identify critical information about environment, volume, users, and requirements
- Review checklists and resources to aid in collecting requirements
Module 3 – Infrastructure Planning: Index Design
- Design and size indexes
- Estimate storage requirements
- Identify relevant apps
Module 4 – Infrastructure Planning: Resource Planning
- List sizing factors for servers
- Describe how reference hardware is used to scale deployments
- Identify the impact of clustering for index replication and for search heads
Module 5 - Clustering Overview
- Describe the different clustering capabilities
- Introduce the concepts of indexer and search head clustering
Module 6 - Forwarder and Deployment Best Practices
- Review types of forwarders
- Describe how to manage forwarder installation
- Review configuration management for all Splunk components, using Splunk deployment tools
- Provide best practices for a Splunk deployment
Module 7 - Integration
- Describe integration methods
- Identify common integration points
Module 8 – Performance Monitoring and Tuning
- Use the Monitoring Console to track the performance of your test environment
- List options to fine tune performance for production environment
Module 9 – Use Cases
- Provide example architecture topologies
- Discuss different architecture options based on use case
Prerequisites
To be successful, students should have a solid understanding of the following courses:
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- What Is Splunk?
- Intro to Splunk
- Using Fields
- Introduction to Knowledge Objects
- Creating Knowledge Objects
- Creating Field Extractions
- Splunk System Administration
- Splunk Data Administration