Cybe Security Awareness Program

Splunk User and Administration Training

Course Overview

This Splunk User and Admin Training includes concepts which are required for both Splunk Users and Splunk Administrators. By the end of this training, you will learn their roles, responsibilities and be ready for implementation.

Splunk User (Developer) training teaches you how to search and navigate in Splunk, use fields, get statistics from your data, create reports, dashboards, lookups, and alerts. Scenario-based examples and hands-on challenges will enable you to create robust searches, reports, and charts. It will also introduce you to Splunk's datasets features and Pivot interface.

Splunk Data Administrators training teaches you how to getting data into Splunk Indexers. The course provides the knowledge of Splunk forwarders and methods to get remote data into Splunk indexers. It covers installation, configuration, management, monitoring, and troubleshooting of Splunk forwarders and Splunk Deployment Server components.

Splunk System Administrators teaches you how to manage Splunk Enterprise environment. The course provides the knowledge of Splunk license manager, indexers and search heads. It covers configuration, management, and monitoring core Splunk Enterprise components.

Course Objective

After completing of this training program, you should be able to:-

  • Understand Splunk Power User/ Admin concepts
  • Apply various Splunk techniques to visualize data using different graphs and dashboards
  • Implement Splunk in the organization to Analyze and Monitor systems for operational intelligence
  • Configure alerts and reports for monitoring purposes
  • Troubleshoot different application logs issues using SPL (Search Processing Language)
  • Implement Splunk Indexers, Search Heads, Forwarder, Deployment Servers & Deployers

Who Should Attend

The training program is ideal for those working in positions such as, but not limited to -

  • IT Operations, IT Monitoring, IT Support, & Data Center teams
  • Data Analysts who want to gain knowledge of Splunk development for creating Apps and Dashboards

Course Duration

  • 40 Hours.

Course Content

User (Development) Training (2 Days * 8 Hours)

  • Introduction to Spunk’s interface
  • Basic searching
  • Using fields in searches
  • Search fundamentals
  • Transforming commands
  • Creating reports and dashboards
  • Datasets
  • Creating and using lookups
  • Scheduled Reports
  • Alerts
  • Using Pivot

SIEM Data Administration Training (3 Days * 8 Hours)

  • Introduction to Data administration
  • Getting Data in-staging
  • Forwarder configuration
  • Forwarder management
  • Monitor inputs
  • Network and scripted inputs
  • Fine-tuning inputs
  • Parsing phase and data preview
  • Manipulating Raw data
  • Supporting Knowledge objects

Splunk System Administration Training

  • Splunk deployment Overview
  • Licensee management
  • Splunk Apps
  • Splunk Configuration File
  • Splunk Indexes
  • Splunk Index management
  • Splunk User management
  • Configuring Basic Forwarding
  • Distributed Search
  • Introduction to Splunk Cluster