Splunk Enterprise 8.2 System Administration

Splunk Enterprise 8.2 System Administration

Upcoming Classes

Online

Instructor-led online training

Location Sep 2021 Oct 2021 Nov 2021 Dec 2021 Jan 2022 Feb 2022 Mar 2022
EMEA UK Time - Virtual Sep 27 – Sep 28
Oct 4 – Oct 5
Oct 11 – Oct 12
Oct 11 – Oct 12
Oct 25 – Oct 26
Nov 1 – Nov 2
Nov 1 – Nov 2
Nov 8 – Nov 9
Nov 15 – Nov 16
Nov 22 – Nov 23
Nov 29 – Nov 30
Dec 6 – Dec 7
Dec 6 – Dec 7
Dec 13 – Dec 14
Jan 3 – Jan 4
Jan 3 – Jan 4
Jan 10 – Jan 11
Jan 10 – Jan 11
Jan 17 – Jan 18
Jan 24 – Jan 25
Jan 31 – Feb 1
Jan 31 – Feb 1
AMER Pacific Time - Virtual Sep 27 – Sep 28
Oct 4 – Oct 5
Oct 11 – Oct 12
Oct 25 – Oct 26
Nov 1 – Nov 2
Nov 1 – Nov 2
Nov 8 – Nov 9
Nov 15 – Nov 16
Nov 29 – Nov 30
Dec 6 – Dec 7
Dec 13 – Dec 14
Jan 3 – Jan 4
Jan 10 – Jan 11
Jan 17 – Jan 18
Jan 24 – Jan 25
Jan 31 – Feb 1
APAC Singapore - Virtual Oct 4 – Oct 5
Oct 25 – Oct 26
Nov 8 – Nov 9
Nov 22 – Nov 23
Dec 6 – Dec 7
Jan 3 – Jan 4
Jan 10 – Jan 11
Jan 24 – Jan 25
AMER Eastern Time - Virtual Oct 4 – Oct 5
Oct 11 – Oct 12
Oct 18 – Oct 19
Oct 25 – Oct 26
Nov 1 – Nov 2
Nov 8 – Nov 9
Nov 15 – Nov 16
Nov 29 – Nov 30
Dec 6 – Dec 7
Dec 13 – Dec 14
Jan 3 – Jan 4
Jan 10 – Jan 11
Jan 17 – Jan 18
Jan 24 – Jan 25
Jan 31 – Feb 1
AMER Central Time - Virtual (Spanish) Oct 4 – Oct 5
AMER Eastern Time - Virtual (Spanish) Nov 8 – Nov 9

Australia

Location Sep 2021 Oct 2021 Nov 2021 Dec 2021 Jan 2022 Feb 2022 Mar 2022
Ingeniq - Online Oct 11 – Oct 12
Nov 8 – Nov 9
Dec 13 – Dec 14

Japan

Location Sep 2021 Oct 2021 Nov 2021 Dec 2021 Jan 2022 Feb 2022 Mar 2022
Japan Third Party Co.,Ltd. Oct 18 – Oct 19
Dec 13 – Dec 14

Summary

This 2 virtual day course is designed for system administrators who are responsible for managing the Splunk Enterprise environment. The course provides the fundamental knowledge of Splunk license manager, indexers and search heads. It covers configuration, management, and monitoring core Splunk Enterprise components.

Description

  • Splunk Deployment Overview
  • License Management
  • Splunk Apps
  • Splunk Configuration Files
  • Users, Roles, and Authentication
  • Getting Data In
  • Distributed Search

Duration

2 Days

Objectives

Module 1 - Splunk Server Deployment

  • Provide an overview of Splunk
  • Identify Splunk Enterprise components
  • Identify the types of Splunk deployments
  • List the steps to install Splunk
  • Use Splunk CLI commands

Module 2 - Splunk Server Monitoring

  • Enable the Monitoring Console (MC)
  • Identify Splunk license types
  • Describe license violations
  • Add and remove licenses
  • Use Splunk Diag

Module 3 - Splunk Apps

  • Describe Splunk apps and add-ons
  • Install an app on a Splunk instance
  • Manage app accessibility and permissions

Module 4 - Splunk Configuration Files

  • Describe Splunk configuration directory structure
  • Understand configuration layering process
  • Use btool to examine configuration settings

Module 5 - Splunk Indexes

  • Learn how Splunk indexes function
  • Identify the types of index buckets
  • Add and work with indexes
  • Overview of metrics index

Module 6 - Splunk Index Management

  • Review Splunk Index Management basics
  • Identify data retention recommendations
  • Identify backup recommendations
  • Move and delete index data
  • Describe the use of the Fishbucket
  • Restore a frozen bucket

Module 7 - Splunk User Management

  • Add Splunk users using native authentication
  • Describe user roles in Splunk
  • Create a custom role
  • Manage users in Splunk

Module 8 - Configuring Basic Forwarding

  • Identify forwarder configuration steps
  • Configure a Universal Forwarder
  • Understand the Deployment Server

Module 9 - Distributed Search

  • Describe how distributed search works
  • Describe the roles of the search head and search peers

 

Prerequisites

Required:

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2

 

Onsite Training

For groups of three or more

Request Quote

Public Training

EMEA UK Time - Virtual

AMER Pacific Time - Virtual

APAC Singapore - Virtual

AMER Eastern Time - Virtual

AMER Central Time - Virtual (Spanish)

Chatswood, NSW

Tokyo

AMER Eastern Time - Virtual (Spanish)


Don't see a date that works for you?

Request Class