Troubleshooting Splunk Enterprise 9.0
Upcoming Classes
Online
Instructor-led online training

Summary
This lab-oriented class is designed to help you gain troubleshooting experience before attending more advanced courses. You will debug a distributed Splunk Enterprise environment using the live system.
This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or Splunk premium apps.
Description
- Splunk Troubleshooting Methods and Tools
- Indexing Problems
- Input Configuration Problems
- Deployment Problems
- License, Upgrade, and User Management Problems
- Search Management Problems
- User Search Problems
Objectives
Module 1 – Splunk Troubleshooting Methods and Tools
- Describe the Splunk Troubleshooting Approach
- List Splunk Diagnostic Resources and Tools
- Create and Splunk a Diag
- Identify RapidDiag
Module 2 – Indexing Problems
- Discover Splunk Deployment Topology and its Server Roles
- Identify Where to Check the Index-Time Pipeline Status
- Use the metrics.log to Clarify the Index-Time Problem
Module 3 – Input Configuration Problems
- Data input issues
- Troubleshooting inputs with Monitoring Console
Module 4 – Deployment and Forwarder Problems
- Deployment Server Issues
- Forwarding and Receiving Issues
Module 5 – License, Upgrade, and User Management Problems
- Installation issues
- Upgrade considerations
- Splunk licensing Issues
- Splunk roles and user management issues
Module 6 – Search Head Management Problems
- Troubleshoot Distributed Search Issues
- Identify Job Scheduling Problems
- Learn to Diagnose Crashing Problems
- Describe How to Prioritize Resources for Critical Splunk Processes
Module 7 – User Search Problems
- Identify the types of search problems
- Isolate and troubleshoot search problems
Prerequisites
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- What Is Splunk?
- Intro to Splunk
- Using Fields
- Scheduling Reports and Alerts
- Introduction to Knowledge Objects
- Creating Knowledge Objects
- Creating Field Extractions
- Splunk Enterprise System Administration
- Splunk Enterprise Data Administration