Troubleshooting Splunk Enterprise 7.3

Troubleshooting Splunk Enterprise 7.3

Summary

This 2-virtual day course is designed for Splunk administrators. It covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available on Splunk Enterprise 7.3.


This lab-oriented class is designed to help you gain troubleshooting experience before attending more advanced courses. You will debug a distributed Splunk Enterprise environment using the live system.


This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or Splunk premium apps.

Description

  • Splunk Troubleshooting Methods and Tools
  • Indexing Problems
  • Input Configuration Problems
  • Deployment Problems
  • License, Upgrade, and User Management Problems
  • Search Management Problems
  • User Search Problems

Duration

2 Days

Objectives

Module 1 – Splunk Troubleshooting Methods and Tools

  • Splunk support resources
  • Splunk troubleshooting approach
  • Splunk diagnostic resources and tools

Module 2 – Indexing Problems

  • Splunk deployment topology
  • Index-time pipeline status
  • Metrics.log

Module 3 – Input Configuration Problems

  • Data input issues
  • Troubleshooting inputs with Monitoring Console

Module 4 – Deployment Problems

  • Deployment server issues
  • Forwarding and receiving issues

Module 5 – License, Upgrade, and User Management Problems

  • Installation issues
  • Upgrade considerations
  • Splunk licensing issues
  • Directory integration issues
  • Splunk roles and user management issues

Module 6 – Search Management Problems

  • Distributed search issues
  • Knowledge bundle replication issues
  • Job scheduling issues
  • Splunk crash issues
  • Splunk Workload Management

Module 7 – User Search Problems

  • Search issues
  • Troubleshooting searches with Job Inspector

Prerequisites

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2
  • Splunk System Administration
  • Splunk Data Administration
  • Strongly recommended:
  • Architecting Splunk Enterprise Deployments

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Pacific Time - Virtual

EMEA Coordinated Universal Time (GMT) - Virtual

APAC Singapore - Virtual

AMER Eastern Time - Virtual

Ingeniq


Don't see a date that works for you?

Request Class