Detailed course brochure attached. Any questions please contact.
Splunk Course Details
Section 1. Splunk Fundamentals
Introduction to Splunk Enterprise
Splunk Architecture - Intro
Installation & Configuration
Importing Data to Splunk
Search Processing Language (SPL)
Splunk Search Assistant
Understanding Add-Ons and Apps
Splunk Add-On for AWS
Splunk App for AWS
Overview of Dashboards and Panels
Splunk Alerts
Section 2. Splunk Architecture
Directory Structure of Splunk
Splunk Configuration Directories
Splunk Configuration Precedence
Splunk Configuration Precedence - Apps and Locals
Btool Usage & commands
Section 3. Splunk Indexes
Introduction to Indexes
Types of Indexes
Creating New Indexes
Bucket Lifecycle
Warm to Cold Bucket Migration
Archiving Data to Frozen Path
Thawing Process
Fish Bucket
Splunk Workflow Actions
Section 4. User, Roles & Security
Creating Users
User Access Control
Creating Custom Roles & Capabilities
Section 5. Splunk Forwarder
Overview of Universal Forwarder
Installing Universal Forwarder in Linux
Challenges in Forwarder Management
Introduction to Deployment Server
Server Class and Deployment Apps
Creating Custom Add-Ons for deployment
Pushing Splunk Linux Add-On via Deployment Server
Section 6. Distributed Splunk Architecture
Overview of Distributed Splunk Architecture
Understanding License Master
Implementing License Master
License Pools
Indexer Cluster Overview
Search Cluster Overview
Splunk Monitoring Console
Section 7. Indexer Clustering
Overview of Indexer Clustering
Deploying Infrastructure for Indexer Cluster
Document - Deploying Indexer Cluster Docker Containers
Master Indexer
Peer Indexers
Testing Replication and Failover capabilities
Configuration Bundle
Forwarding Logs to Indexer Cluster
Indexer Discovery
Splunk HTTP Event Collector
Section 8. Search Head Clustering
Overview of Search Head Clusters
Deploying Infrastructure for Search Head Cluster
Configuring Cluster Setup on Search Heads
Search Head Clustering Setup - Document
Validating Search Head Replication
Pushing Artifacts through Deployer
Connecting Search Head Cluster to Indexer Cluster
Section 9. Splunk Data Model
Splunk Data Model Intro
Creating Data Model
Pivot Usage
Section 10: Extended Usage of Config files
Importance of Source Types
Interactive Field Extractor (IFX)
Using props.conf
Using transforms.conf
Index Time Field Extraction with Examples
Search Time Field Extraction with Examples
Sample Log - MySQL Error Logs
Splunk Event Types
Tags
Splunk Events Types Priority and Coloring Scheme
Splunk Lookups
Add On: Section 11: Regex (Regular Expression) Course
Understanding Regular Expressions
How to use Regex
Regex - Exercise
Parsing Web Server Logs & Named Group Expression