Splunk 8.2 Cluster Administration
Upcoming Classes
Online
Instructor-led online training
Location | Jul 2022 | Aug 2022 | Sep 2022 | Oct 2022 | Nov 2022 | Dec 2022 | Jan 2023 |
---|---|---|---|---|---|---|---|
APAC Singapore - Virtual |
Jul 13 – Jul 15 |
Aug 8 – Aug 10 Aug 31 – Sep 2 |
Sep 26 – Sep 28 |
Oct 17 – Oct 19 | |||
EMEA UK Time - Virtual |
Jul 13 – Jul 15 | ||||||
AMER Pacific Time - Virtual |
Jul 13 – Jul 15 Jul 27 – Jul 29 | ||||||
AMER Eastern Time - Virtual |
Jul 20 – Jul 22 Jul 27 – Jul 29 | ||||||
APAC Sydney - Virtual |
Aug 31 – Sep 2 |

Summary
This 3-virtual day course is for an experienced Splunk Enterprise administrator who is new to Splunk Clusters. The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment. It covers installation, configuration, management, and monitoring of Splunk clusters.
While Splunk Clusters are supported in Windows environments, the class lab environment is running Linux instances only.
Description
- Large-scale Splunk Deployment Overview
- Single-site Indexer Cluster
- Indexer Cluster Management and Administration
- Forwarder Configuration
- Search Head Cluster
- Search Head Cluster Management and Administration
- KV Store Collection and Lookup Management
- SmartStore Implementation Overview
Objectives
Module 1 – Large-scale Splunk Deployment Overview
- Factors that affecting deployment design
- How Splunk Enterprise can scale
- Splunk License Master
Module 2 – Single-site Indexer Cluster
- How Splunk single-site indexer clusters work
- Indexer cluster components and terms
- Splunk single-site indexer cluster configuration
- Splunk indexer cluster log channels
Module 3 – Multisite Indexer Cluster
- How Splunk multisite indexer clusters work
- Multisite indexer cluster terms
- Multisite indexer cluster configuration
- Optional multisite indexer cluster configurations
Module 4 – Indexer Cluster Management and Administration
- Peer offline and decommission
- Master app bundles
- Indexer cluster storage utilization options
- Site mapping
- Monitoring Console for indexer cluster environment
Module 5 – Forwarder Management
- Indexer discovery
- Optional indexer discovery configurations
- Volume-based forwarder load balancing
Module 6 – Search Head Cluster
- Splunk search head cluster overview
- Search head cluster configuration
Module 7 – Search Head Cluster Management and Administration
- Search head cluster deployer
- Captaincy transfer
- Search head member addition and decommissioning
- Monitoring Console for Search Head Cluster
Module 8 – KV Store Collection and Lookup Management
- KV Store collection in Splunk clusters
- KV Store monitoring with Monitoring Console
Module 9 – SmartStore Implementation
- SmartStore architecture overview
- Deploy and manage SmartStore
Prerequisites
To be successful, students should have a solid understanding of the following courses:
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- What Is Splunk?
- Intro to Splunk
- Using Fields
- Scheduling Reports and Alerts
- Visualizations
- Leveraging Lookups and Subsearches
- Search Under the Hood
- Introduction to Knowledge Objects
- Creating Knowledge Objects
- Enriching Data with Lookups
- Data Models
- Introduction to Dashboards
- Splunk System Administration
- Splunk Data Administration
- Troubleshooting Splunk Enterprise