Course Summary

The Splunk Enterprise Administration course is suitable for you with Splunk On-Prem installations. This course is a bundle of 2 key modules Splunk Enterprise System Administration (SESA) and Splunk Enterprise Data Administration (SEDA)

You will gain skills like:

• Installation, configuration, and maintenance of Splunk Enterprise
• User and role management in Splunk
• Data ingestion and indexing optimization
• Troubleshooting common Splunk issues
• Implementing high availability and disaster recovery strategies

Module 1: Splunk Admin Basics
• Identify Splunk components

Module 2: License Management
• Identify license types
• Understand license violations

Module 3: Splunk Configuration Files
• Describe Splunk configuration directory structure
• Understand configuration layering
• Understand configuration precedence
• Use btool to examine configuration settings

Module 4: Splunk Indexes
• Describe index structure
• List types of index buckets
• Check index data integrity
• Describe indexes.conf options
• Describe the fishbucket
• Apply a data retention policy

Module 5: Splunk User Management
• Describe user roles in Splunk
• Create a custom role
• Add Splunk users

Module 6: Splunk Authentication Management
• Integrate Splunk with LDAP
• List other user authentication options
• Describe the steps to enable multifactor authentication in Splunk

Module 7: Getting Data In
• Describe the basic settings for an input
• List Splunk forwarder types
• Configure the forwarder
• Add an input to UF using CLI

Module 8: Distributed Search
• Describe how distributed search works
• Explain the roles of the search head and search peers
• Configure a distributed search group
• List search head scaling options

Module 9: Getting Data In – Staging
• List the three phases of the Splunk Indexing process
• List Splunk input options

Module 10: Configuring Forwarders
• Configure Forwarders
• Identify additional Forwarder options

Module 11: Forwarder Management
• Explain the use of deployment management
• Describe Splunk Deployment Server
• Manage forwarders using deployment apps
• Configure deployment clients
• Configure client groups
• Monitor forwarder management activities

Module 12: Monitor Inputs
• Create file and directory monitor inputs
• Use optional settings for monitor inputs
• Deploy a remote monitor input

Module 13: Network and Scripted Inputs
• Create network (TCP and UDP) inputs
• Describe optional settings for network inputs
• Create a basic scripted input

Module 14: Agentless Inputs
• Creating Windows Management Instrumentation (WMI) inputs
• Describe HTTP Event Collector

Module 15: Fine Tuning Inputs
• Understand the default processing that occurs during input phase
• Configure input phase options, such as sourcetype fine-tuning and character set encoding

Module 16: Parsing Phase and Data
• Understand the default processing that occurs during parsing
• Optimize and configure event line breaking
• Explain how timestamps and time zones are extracted or assigned to events
• Use Data Preview to validate event creation during the parsing phase

Module 17: Manipulating Raw Data
• Explain how data transformations are defined and invoked
• Use transformations with props.conf and transforms.conf to:
• Mask or delete raw data as it is being indexed
• Override sourcetype or host based upon event values
• Route events to specific indexes based on event content
• Prevent unwanted events from being indexed
• Use SEDCMD to modify raw data

Before attending this course, you have to take the following course: Splunk Power User to be certified

Splunk Enterprise Administration: Level: Professional Prerequisites: Splunk Core Certified Power User Length: 60 minutes Format: 56 multiple choice questions

Following your booking, a confirmation message will be sent to all participants, ensuring you're well-informed of your successful enrollment. Calendar placeholders will also be dispatched to assist you in scheduling your commitments around the course. Rest assured, all course materials and access to necessary labs or platforms will be provided no later than one week before the course begins, allowing you ample time to prepare and engage fully with the learning experience ahead.

Our comprehensive training package includes all the necessary materials and resources to facilitate a full learning experience. Enrollees will be provided with detailed course content, encompassing a wide array of topics to ensure a thorough understanding of the subject matter. Additionally, participants will receive a certificate of completion to recognize their dedication and hard work. It's important to note that while the course fee covers all training materials and experiences, the examination fee for certification is not included but can be purchased separately.

Questions About This Course?