Using Splunk Stream Processor Service (SPS)

Using Splunk Stream Processor Service (SPS)

Upcoming Classes


Instructor-led online training

Location Jan 2022 Feb 2022 Mar 2022 Apr 2022 May 2022 Jun 2022 Jul 2022
AMER Pacific Time - Virtual Feb 23 – Feb 24
AMER Eastern Time - Virtual Apr 14 – Apr 15


This 2-day course is designed for the experienced Splunk Cloud administrators who are new to Splunk Stream Processor Service. This hands-on class provides the fundamentals of extending Splunk Cloud data ingestion options with a stream processing solution. With Splunk SPS, you can transform, enrich, and analyze your data before it reaches its final destination. It covers source and sink configurations, and building pipelines with templates.


  • Introduction to SPS
  • Accessing Splunk Cloud Services (SCS) Tenant Services
  • SPS Overview
  • Configuring SPS Source Connections
  • Configuring SPS Sink Connections
  • Building SPS Pipelines
  • Splunk Forwarder Pipeline


2 Days


Module 1 - Introduction to SPS

  • Review Splunk SaaS benefits and features
  • Explain the differences between Splunk Cloud and Splunk Cloud Services
  • Identify the purpose of Stream Processor Service
  • Understand the SPS licensing model

Module 2 - Accessing SCS Tenant Services

  • List the Authentication and Authorization differences between Splunk Cloud and SCS
  • Manage SCS groups and permissions
  • Invite SPS users
  • Navigate in SCS and SPS

Module 3 - SPS Overview

  • Identify basic SPS concepts and navigation
  • Configure scloud

Module 4 - Configure SPS Source Connections

  • Send data to SPS Ingest Service (REST API)
  • Ingest data from Splunk HTTP Event Collector (HEC) sources
  • Add source connections for 3rd-party data sources

Module 5 - Configuring SPS Sink Connections

  • Configure sink connections for Splunk indexers
  • Send observability data to Splunk IM and Splunk APM
  • Add sink connections for 3rd-party destinations
  • Create a source-to-Splunk pass through pipeline

Module 6 - Building SPS Pipelines

  • Understand the use cases for default templates
  • Describe the basic elements of a SPS pipeline
  • List SPS pipeline streaming functions
  • Use scalar functions to tune data types
  • Filter, manipulate, and route streaming data

Module 7 - Splunk Forwarder Pipeline

  • Connect Splunk forwarders to SPS Forwarder Service
    • Convert the Forwarder Credentials App
  • Manipulate pipeline options with SPS templates
    • Transform
    • Obfuscate
    • Convert logs to metrics


  • Splunk Cloud Administration
  • Or, Transitioning to Splunk Cloud

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Pacific Time - Virtual

AMER Eastern Time - Virtual

Don't see a date that works for you?

Request Class