SlideShare a Scribd company logo
Splunk Education Services
Advanced Splunk 5.0 AdministrationThis nine hour course follows the Splunk Administration course. The
focus in this class is the knowledge, best practices, and
configuration details for Splunk administration in a medium to large
deployment environment. In this class you will learn advanced input
configuration options, Splunk's data processing flow, optimized
indexing configurations, alternative authentication methods,
security, and troubleshooting.
Course Topics
๏‚ง Splunk hardware and topology options
๏‚ง Advanced use and configuration of Splunk forwarders
๏‚ง Splunkโ€™s Deployment Server
๏‚ง Advanced data input options
๏‚ง Data inputs advanced configuration
๏‚ง Advanced configuration of Splunk data stores
๏‚ง Authentication
๏‚ง How and what to secure in Splunk
๏‚ง Where to get help
Course Prerequisites
๏‚ง Using Splunk
๏‚ง Administrating Splunk
Class Format
Instructor-led lecture with labs. Delivered via virtual classroom or at
your site.
Course Objectives
Lesson 1 โ€“ Hardware and Topology
๏‚ง Identify Splunk hardware recommendations
๏‚ง Explore Splunk topology recommendations
๏‚ง Describe distributed search and search head pooling
Lesson 2 โ€“ Forwarders
๏‚ง Configure Splunk forwarders using outputs.conf
๏‚ง Configure load balancing
๏‚ง Secure and compress forwarder feeds and set cache size
๏‚ง Enable indexer acknowledgement
๏‚ง Leverage 3rd party systems
Lesson 3 โ€“ Deployment Server
๏‚ง Understand Deployment Server terminology and topology
๏‚ง Use server classes to send custom config files to all types of
Splunk installs
๏‚ง Configure deployment clients
๏‚ง Create and distribute deployment bundles
Lesson 4 โ€“ Inputs
๏‚ง Use wildcards
๏‚ง Use whitelists and blacklists to limit monitor data inputs
๏‚ง Configure scripted inputs
๏‚ง Understand file system change monitoring
Lesson 5 - Data Processing
๏‚ง Describe how data moves through Splunk
๏‚ง Understand default processing
๏‚ง Optimize and configure event line breaking
๏‚ง Explain how Splunk determines and assigns time zones
๏‚ง Use the Data Preview feature to configure a custom data input
Lesson 6 - Event-level Data Transformations
๏‚ง Explain how data transformations are defined and invoked
๏‚ง Identify and explain how keys are used in transforms.conf
๏‚ง Dynamically set source type based on values
๏‚ง Automatically route events to an index based on values
๏‚ง Prevent unwanted events from being indexed
๏‚ง Mask data values within events
Lesson 7 - Index Replication
๏‚ง Describe index replication
๏‚ง Define the terms: replication factor and search factor
๏‚ง Explain how data flows in a replicated environment
๏‚ง Explain what happens if an indexer goes off-line
๏‚ง Explain how to configure and deploy a cluster
Lesson 8 - Authentication
๏‚ง Review native Splunk authentication
๏‚ง Use LDAP
๏‚ง Use Active Directory
๏‚ง Configure SSO
Lesson 9 - Security
๏‚ง Identify what you can secure in Splunk
๏‚ง Understand SSL and Splunk
๏‚ง Learn about user group and index security
๏‚ง Identify and secure the audit log
๏‚ง Understand archive data signing
Lesson 10 - Troubleshooting
๏‚ง Set specific internal logging levels
๏‚ง Identify and solve common issues
๏‚ง Learn how to get community help with Splunk
๏‚ง Understand how to contact Splunk Support
Splunk Education Services
Splunk Education Tracks
User: For all day-to-day Splunk users including customer support
staff, developers, systems administrators and management.
Administrator: For administrators of Splunk itself. (Administrators
of other systems who will just be using Splunk should take the User
track.)
Architect: For architects who will be designing Splunk
deployments, including architects on staff at customer deployments
as well as partner professional services personnel.
Developer: For developers who will integrate, customize and
extend Splunk using its XML templates and advanced configuration
bundling.
Support Engineer: For Splunk OEM and channel partner support
staff who will be providing first line support for Splunk.
Tracks User Administrator Architect Developer
Support
Engineer
Using Splunk โœ“ โœ“ โœ“ โœ“ โœ“
Searching and
Reporting with Splunk
โœ“ โœ“ โœ“ โœ“
Administrating Splunk โœ“ โœ“ โœ“
Advanced Splunk
Administration
โœ“ โœ“ โœ“
Architecting and
Deploying Splunk
โœ“ โœ“
Developing Apps with
Splunk
โœ“ โœ“ โœ“
Splunk Architect
Certification Lab
โœ“
Supporting Splunk โœ“
About Splunk
Splunk is software that indexes,
manages and enables you to search
data from any application, server or
network device in real time.
Visit our website at www.splunk.com
to download your own free copy.
Splunk Inc.
250 Brannan
San Francisco, CA 94107
866.GET.SPLUNK
(866.438.7758)
sales@splunk.com
support@splunk.com
Ad

More Related Content

What's hot (20)

Splunk for Developers
Splunk for DevelopersSplunk for Developers
Splunk for Developers
Splunk
ย 
Customer Presentation - Financial Services Organization
Customer Presentation - Financial Services OrganizationCustomer Presentation - Financial Services Organization
Customer Presentation - Financial Services Organization
Splunk
ย 
Taking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - ArchitectureTaking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - Architecture
Splunk
ย 
SplunkLive! San Francisco Dec 2012 - Intuit
SplunkLive! San Francisco Dec 2012 - IntuitSplunkLive! San Francisco Dec 2012 - Intuit
SplunkLive! San Francisco Dec 2012 - Intuit
Splunk
ย 
Splunk Enterprise 6.3 - Splunk Tech Day
Splunk Enterprise 6.3 - Splunk Tech DaySplunk Enterprise 6.3 - Splunk Tech Day
Splunk Enterprise 6.3 - Splunk Tech Day
Zivaro Inc
ย 
Machine Data 101
Machine Data 101Machine Data 101
Machine Data 101
Splunk
ย 
Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)
Splunk
ย 
Taking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout SessionTaking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
ย 
Customer Presentation
Customer PresentationCustomer Presentation
Customer Presentation
Splunk
ย 
Splunk @ Adobe
Splunk @ AdobeSplunk @ Adobe
Splunk @ Adobe
Splunk
ย 
What's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-BoardingWhat's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-Boarding
Splunk
ย 
Customer Presentation
Customer PresentationCustomer Presentation
Customer Presentation
Splunk
ย 
Splunk Architecture overview
Splunk Architecture overviewSplunk Architecture overview
Splunk Architecture overview
Alex Fok
ย 
Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS)
Splunk
ย 
Cisco UCS and Splunk Workshop
Cisco UCS and Splunk WorkshopCisco UCS and Splunk Workshop
Cisco UCS and Splunk Workshop
Robb Boyd
ย 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
ย 
Splunk live beginner training nyc
Splunk live beginner training nycSplunk live beginner training nyc
Splunk live beginner training nyc
Dimitri McKay - CISSP
ย 
SplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners Session
Splunk
ย 
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire DataSplunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk
ย 
SplunkLive! London 2016 Splunk Overview
SplunkLive! London 2016 Splunk OverviewSplunkLive! London 2016 Splunk Overview
SplunkLive! London 2016 Splunk Overview
Splunk
ย 
Splunk for Developers
Splunk for DevelopersSplunk for Developers
Splunk for Developers
Splunk
ย 
Customer Presentation - Financial Services Organization
Customer Presentation - Financial Services OrganizationCustomer Presentation - Financial Services Organization
Customer Presentation - Financial Services Organization
Splunk
ย 
Taking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - ArchitectureTaking Splunk to the Next Level - Architecture
Taking Splunk to the Next Level - Architecture
Splunk
ย 
SplunkLive! San Francisco Dec 2012 - Intuit
SplunkLive! San Francisco Dec 2012 - IntuitSplunkLive! San Francisco Dec 2012 - Intuit
SplunkLive! San Francisco Dec 2012 - Intuit
Splunk
ย 
Splunk Enterprise 6.3 - Splunk Tech Day
Splunk Enterprise 6.3 - Splunk Tech DaySplunk Enterprise 6.3 - Splunk Tech Day
Splunk Enterprise 6.3 - Splunk Tech Day
Zivaro Inc
ย 
Machine Data 101
Machine Data 101Machine Data 101
Machine Data 101
Splunk
ย 
Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)Power of Splunk Search Processing Language (SPL)
Power of Splunk Search Processing Language (SPL)
Splunk
ย 
Taking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout SessionTaking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout Session
Splunk
ย 
Customer Presentation
Customer PresentationCustomer Presentation
Customer Presentation
Splunk
ย 
Splunk @ Adobe
Splunk @ AdobeSplunk @ Adobe
Splunk @ Adobe
Splunk
ย 
What's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-BoardingWhat's New in 6.3 + Data On-Boarding
What's New in 6.3 + Data On-Boarding
Splunk
ย 
Customer Presentation
Customer PresentationCustomer Presentation
Customer Presentation
Splunk
ย 
Splunk Architecture overview
Splunk Architecture overviewSplunk Architecture overview
Splunk Architecture overview
Alex Fok
ย 
Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS) Splunk in the Cisco Unified Computing System (UCS)
Splunk in the Cisco Unified Computing System (UCS)
Splunk
ย 
Cisco UCS and Splunk Workshop
Cisco UCS and Splunk WorkshopCisco UCS and Splunk Workshop
Cisco UCS and Splunk Workshop
Robb Boyd
ย 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
ย 
Splunk live beginner training nyc
Splunk live beginner training nycSplunk live beginner training nyc
Splunk live beginner training nyc
Dimitri McKay - CISSP
ย 
SplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners Session
Splunk
ย 
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire DataSplunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk
ย 
SplunkLive! London 2016 Splunk Overview
SplunkLive! London 2016 Splunk OverviewSplunkLive! London 2016 Splunk Overview
SplunkLive! London 2016 Splunk Overview
Splunk
ย 

Similar to Advanced Splunk Administration (20)

Administering Splunk course
Administering Splunk courseAdministering Splunk course
Administering Splunk course
Greg Hanchin
ย 
Administering splunk 43 course
Administering splunk 43 courseAdministering splunk 43 course
Administering splunk 43 course
Greg Hanchin
ย 
Advanced searching and reporting 50 course
Advanced searching and reporting 50 course Advanced searching and reporting 50 course
Advanced searching and reporting 50 course
Greg Hanchin
ย 
Splunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class descriptionSplunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class description
Greg Hanchin
ย 
Using splunk43course
Using splunk43courseUsing splunk43course
Using splunk43course
Greg Hanchin
ย 
Using Splunk course outline
Using Splunk course outline Using Splunk course outline
Using Splunk course outline
Greg Hanchin
ย 
Splunk Searching and Reporting Class Details
Splunk Searching and Reporting Class DetailsSplunk Searching and Reporting Class Details
Splunk Searching and Reporting Class Details
Greg Hanchin
ย 
Splunk Searching and reporting 43course
Splunk Searching and reporting 43courseSplunk Searching and reporting 43course
Splunk Searching and reporting 43course
Greg Hanchin
ย 
Learn splunk online training
Learn splunk online training Learn splunk online training
Learn splunk online training
AngelinaJoile1
ย 
Splunk best practices
Splunk best practicesSplunk best practices
Splunk best practices
Jilali HARITI
ย 
Veera
VeeraVeera
Veera
chenvi123
ย 
Splunk Administration Training Certification.pdf
Splunk Administration Training Certification.pdfSplunk Administration Training Certification.pdf
Splunk Administration Training Certification.pdf
Multisoft Virtual Acedamy
ย 
Design and Implement Security Operat.docx
Design and Implement Security Operat.docxDesign and Implement Security Operat.docx
Design and Implement Security Operat.docx
theodorelove43763
ย 
Splunk 6.5.0-pivot tutorial (7)
Splunk 6.5.0-pivot tutorial (7)Splunk 6.5.0-pivot tutorial (7)
Splunk 6.5.0-pivot tutorial (7)
Zoumana Diomande
ย 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
ย 
Splunk Insights
Splunk InsightsSplunk Insights
Splunk Insights
Sunil Kumar
ย 
Updating system administrator skills microsoft windows 2000 windows server 20...
Updating system administrator skills microsoft windows 2000 windows server 20...Updating system administrator skills microsoft windows 2000 windows server 20...
Updating system administrator skills microsoft windows 2000 windows server 20...
LEN Learning Education Network
ย 
Splunk metrics via telegraf
Splunk metrics via telegrafSplunk metrics via telegraf
Splunk metrics via telegraf
Ashvin Pandey
ย 
Sumo Logic Cert Jam - Fundamentals
Sumo Logic Cert Jam - FundamentalsSumo Logic Cert Jam - Fundamentals
Sumo Logic Cert Jam - Fundamentals
Sumo Logic
ย 
Sumo Logic QuickStart
Sumo Logic QuickStartSumo Logic QuickStart
Sumo Logic QuickStart
Sumo Logic
ย 
Administering Splunk course
Administering Splunk courseAdministering Splunk course
Administering Splunk course
Greg Hanchin
ย 
Administering splunk 43 course
Administering splunk 43 courseAdministering splunk 43 course
Administering splunk 43 course
Greg Hanchin
ย 
Advanced searching and reporting 50 course
Advanced searching and reporting 50 course Advanced searching and reporting 50 course
Advanced searching and reporting 50 course
Greg Hanchin
ย 
Splunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class descriptionSplunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class description
Greg Hanchin
ย 
Using splunk43course
Using splunk43courseUsing splunk43course
Using splunk43course
Greg Hanchin
ย 
Using Splunk course outline
Using Splunk course outline Using Splunk course outline
Using Splunk course outline
Greg Hanchin
ย 
Splunk Searching and Reporting Class Details
Splunk Searching and Reporting Class DetailsSplunk Searching and Reporting Class Details
Splunk Searching and Reporting Class Details
Greg Hanchin
ย 
Splunk Searching and reporting 43course
Splunk Searching and reporting 43courseSplunk Searching and reporting 43course
Splunk Searching and reporting 43course
Greg Hanchin
ย 
Learn splunk online training
Learn splunk online training Learn splunk online training
Learn splunk online training
AngelinaJoile1
ย 
Splunk best practices
Splunk best practicesSplunk best practices
Splunk best practices
Jilali HARITI
ย 
Veera
VeeraVeera
Veera
chenvi123
ย 
Splunk Administration Training Certification.pdf
Splunk Administration Training Certification.pdfSplunk Administration Training Certification.pdf
Splunk Administration Training Certification.pdf
Multisoft Virtual Acedamy
ย 
Design and Implement Security Operat.docx
Design and Implement Security Operat.docxDesign and Implement Security Operat.docx
Design and Implement Security Operat.docx
theodorelove43763
ย 
Splunk 6.5.0-pivot tutorial (7)
Splunk 6.5.0-pivot tutorial (7)Splunk 6.5.0-pivot tutorial (7)
Splunk 6.5.0-pivot tutorial (7)
Zoumana Diomande
ย 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
Splunk
ย 
Splunk Insights
Splunk InsightsSplunk Insights
Splunk Insights
Sunil Kumar
ย 
Updating system administrator skills microsoft windows 2000 windows server 20...
Updating system administrator skills microsoft windows 2000 windows server 20...Updating system administrator skills microsoft windows 2000 windows server 20...
Updating system administrator skills microsoft windows 2000 windows server 20...
LEN Learning Education Network
ย 
Splunk metrics via telegraf
Splunk metrics via telegrafSplunk metrics via telegraf
Splunk metrics via telegraf
Ashvin Pandey
ย 
Sumo Logic Cert Jam - Fundamentals
Sumo Logic Cert Jam - FundamentalsSumo Logic Cert Jam - Fundamentals
Sumo Logic Cert Jam - Fundamentals
Sumo Logic
ย 
Sumo Logic QuickStart
Sumo Logic QuickStartSumo Logic QuickStart
Sumo Logic QuickStart
Sumo Logic
ย 
Ad

More from Greg Hanchin (20)

NUTANIX and SPLUNK
NUTANIX and SPLUNKNUTANIX and SPLUNK
NUTANIX and SPLUNK
Greg Hanchin
ย 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
Greg Hanchin
ย 
Splunk for cyber_threat
Splunk for cyber_threatSplunk for cyber_threat
Splunk for cyber_threat
Greg Hanchin
ย 
Splunk for compliance
Splunk for complianceSplunk for compliance
Splunk for compliance
Greg Hanchin
ย 
Advanced Splunk 50 administration
Advanced Splunk 50 administrationAdvanced Splunk 50 administration
Advanced Splunk 50 administration
Greg Hanchin
ย 
Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring
Greg Hanchin
ย 
Splunk forwarders tech_brief
Splunk forwarders tech_briefSplunk forwarders tech_brief
Splunk forwarders tech_brief
Greg Hanchin
ย 
Splunk and map_reduce
Splunk and map_reduceSplunk and map_reduce
Splunk and map_reduce
Greg Hanchin
ย 
Splunk for xen_desktop
Splunk for xen_desktopSplunk for xen_desktop
Splunk for xen_desktop
Greg Hanchin
ย 
Splunk for palo_alto
Splunk for palo_altoSplunk for palo_alto
Splunk for palo_alto
Greg Hanchin
ย 
Splunk for ibtrm
Splunk for ibtrmSplunk for ibtrm
Splunk for ibtrm
Greg Hanchin
ย 
Splunk for fisma
Splunk for fismaSplunk for fisma
Splunk for fisma
Greg Hanchin
ย 
Splunk for f5
Splunk for f5Splunk for f5
Splunk for f5
Greg Hanchin
ย 
Splunk for db_connect
Splunk for db_connectSplunk for db_connect
Splunk for db_connect
Greg Hanchin
ย 
Splunk for active_directory
Splunk for active_directorySplunk for active_directory
Splunk for active_directory
Greg Hanchin
ย 
Splunk app for_windows
Splunk app for_windowsSplunk app for_windows
Splunk app for_windows
Greg Hanchin
ย 
Splunk app for_enterprise_security
Splunk app for_enterprise_securitySplunk app for_enterprise_security
Splunk app for_enterprise_security
Greg Hanchin
ย 
Splunk guide for_iso_27002
Splunk guide for_iso_27002Splunk guide for_iso_27002
Splunk guide for_iso_27002
Greg Hanchin
ย 
Splunk for security
Splunk for securitySplunk for security
Splunk for security
Greg Hanchin
ย 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
Greg Hanchin
ย 
NUTANIX and SPLUNK
NUTANIX and SPLUNKNUTANIX and SPLUNK
NUTANIX and SPLUNK
Greg Hanchin
ย 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
Greg Hanchin
ย 
Splunk for cyber_threat
Splunk for cyber_threatSplunk for cyber_threat
Splunk for cyber_threat
Greg Hanchin
ย 
Splunk for compliance
Splunk for complianceSplunk for compliance
Splunk for compliance
Greg Hanchin
ย 
Advanced Splunk 50 administration
Advanced Splunk 50 administrationAdvanced Splunk 50 administration
Advanced Splunk 50 administration
Greg Hanchin
ย 
Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring
Greg Hanchin
ย 
Splunk forwarders tech_brief
Splunk forwarders tech_briefSplunk forwarders tech_brief
Splunk forwarders tech_brief
Greg Hanchin
ย 
Splunk and map_reduce
Splunk and map_reduceSplunk and map_reduce
Splunk and map_reduce
Greg Hanchin
ย 
Splunk for xen_desktop
Splunk for xen_desktopSplunk for xen_desktop
Splunk for xen_desktop
Greg Hanchin
ย 
Splunk for palo_alto
Splunk for palo_altoSplunk for palo_alto
Splunk for palo_alto
Greg Hanchin
ย 
Splunk for ibtrm
Splunk for ibtrmSplunk for ibtrm
Splunk for ibtrm
Greg Hanchin
ย 
Splunk for fisma
Splunk for fismaSplunk for fisma
Splunk for fisma
Greg Hanchin
ย 
Splunk for f5
Splunk for f5Splunk for f5
Splunk for f5
Greg Hanchin
ย 
Splunk for db_connect
Splunk for db_connectSplunk for db_connect
Splunk for db_connect
Greg Hanchin
ย 
Splunk for active_directory
Splunk for active_directorySplunk for active_directory
Splunk for active_directory
Greg Hanchin
ย 
Splunk app for_windows
Splunk app for_windowsSplunk app for_windows
Splunk app for_windows
Greg Hanchin
ย 
Splunk app for_enterprise_security
Splunk app for_enterprise_securitySplunk app for_enterprise_security
Splunk app for_enterprise_security
Greg Hanchin
ย 
Splunk guide for_iso_27002
Splunk guide for_iso_27002Splunk guide for_iso_27002
Splunk guide for_iso_27002
Greg Hanchin
ย 
Splunk for security
Splunk for securitySplunk for security
Splunk for security
Greg Hanchin
ย 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
Greg Hanchin
ย 
Ad

Recently uploaded (20)

How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
ย 
Rusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond SparkRusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond Spark
carlyakerly1
ย 
Mobile App Development Company in Saudi Arabia
Mobile App Development Company in Saudi ArabiaMobile App Development Company in Saudi Arabia
Mobile App Development Company in Saudi Arabia
Steve Jonas
ย 
Technology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data AnalyticsTechnology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data Analytics
InData Labs
ย 
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
BookNet Canada
ย 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
ย 
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
Alan Dix
ย 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
ย 
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Impelsys Inc.
ย 
AI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global TrendsAI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global Trends
InData Labs
ย 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
ย 
Cyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of securityCyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of security
riccardosl1
ย 
Generative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in BusinessGenerative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in Business
Dr. Tathagat Varma
ย 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
ย 
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
BookNet Canada
ย 
2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx
Samuele Fogagnolo
ย 
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager APIUiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPathCommunity
ย 
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep DiveDesigning Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
ScyllaDB
ย 
Build Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For DevsBuild Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For Devs
Brian McKeiver
ย 
What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...
Vishnu Singh Chundawat
ย 
How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
ย 
Rusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond SparkRusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond Spark
carlyakerly1
ย 
Mobile App Development Company in Saudi Arabia
Mobile App Development Company in Saudi ArabiaMobile App Development Company in Saudi Arabia
Mobile App Development Company in Saudi Arabia
Steve Jonas
ย 
Technology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data AnalyticsTechnology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data Analytics
InData Labs
ย 
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
BookNet Canada
ย 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
ย 
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
AI Changes Everything โ€“ Talk at Cardiff Metropolitan University, 29th April 2...
Alan Dix
ย 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
ย 
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Impelsys Inc.
ย 
AI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global TrendsAI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global Trends
InData Labs
ย 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
ย 
Cyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of securityCyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of security
riccardosl1
ย 
Generative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in BusinessGenerative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in Business
Dr. Tathagat Varma
ย 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
ย 
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
BookNet Canada
ย 
2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx
Samuele Fogagnolo
ย 
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager APIUiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPathCommunity
ย 
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep DiveDesigning Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
Designing Low-Latency Systems with Rust and ScyllaDB: An Architectural Deep Dive
ScyllaDB
ย 
Build Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For DevsBuild Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For Devs
Brian McKeiver
ย 
What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...
Vishnu Singh Chundawat
ย 

Advanced Splunk Administration

  • 1. Splunk Education Services Advanced Splunk 5.0 AdministrationThis nine hour course follows the Splunk Administration course. The focus in this class is the knowledge, best practices, and configuration details for Splunk administration in a medium to large deployment environment. In this class you will learn advanced input configuration options, Splunk's data processing flow, optimized indexing configurations, alternative authentication methods, security, and troubleshooting. Course Topics ๏‚ง Splunk hardware and topology options ๏‚ง Advanced use and configuration of Splunk forwarders ๏‚ง Splunkโ€™s Deployment Server ๏‚ง Advanced data input options ๏‚ง Data inputs advanced configuration ๏‚ง Advanced configuration of Splunk data stores ๏‚ง Authentication ๏‚ง How and what to secure in Splunk ๏‚ง Where to get help Course Prerequisites ๏‚ง Using Splunk ๏‚ง Administrating Splunk Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site. Course Objectives Lesson 1 โ€“ Hardware and Topology ๏‚ง Identify Splunk hardware recommendations ๏‚ง Explore Splunk topology recommendations ๏‚ง Describe distributed search and search head pooling Lesson 2 โ€“ Forwarders ๏‚ง Configure Splunk forwarders using outputs.conf ๏‚ง Configure load balancing ๏‚ง Secure and compress forwarder feeds and set cache size ๏‚ง Enable indexer acknowledgement ๏‚ง Leverage 3rd party systems Lesson 3 โ€“ Deployment Server ๏‚ง Understand Deployment Server terminology and topology ๏‚ง Use server classes to send custom config files to all types of Splunk installs ๏‚ง Configure deployment clients ๏‚ง Create and distribute deployment bundles Lesson 4 โ€“ Inputs ๏‚ง Use wildcards ๏‚ง Use whitelists and blacklists to limit monitor data inputs ๏‚ง Configure scripted inputs ๏‚ง Understand file system change monitoring Lesson 5 - Data Processing ๏‚ง Describe how data moves through Splunk ๏‚ง Understand default processing ๏‚ง Optimize and configure event line breaking ๏‚ง Explain how Splunk determines and assigns time zones ๏‚ง Use the Data Preview feature to configure a custom data input Lesson 6 - Event-level Data Transformations ๏‚ง Explain how data transformations are defined and invoked ๏‚ง Identify and explain how keys are used in transforms.conf ๏‚ง Dynamically set source type based on values ๏‚ง Automatically route events to an index based on values ๏‚ง Prevent unwanted events from being indexed ๏‚ง Mask data values within events Lesson 7 - Index Replication ๏‚ง Describe index replication ๏‚ง Define the terms: replication factor and search factor ๏‚ง Explain how data flows in a replicated environment ๏‚ง Explain what happens if an indexer goes off-line ๏‚ง Explain how to configure and deploy a cluster Lesson 8 - Authentication ๏‚ง Review native Splunk authentication ๏‚ง Use LDAP ๏‚ง Use Active Directory ๏‚ง Configure SSO Lesson 9 - Security ๏‚ง Identify what you can secure in Splunk ๏‚ง Understand SSL and Splunk ๏‚ง Learn about user group and index security ๏‚ง Identify and secure the audit log ๏‚ง Understand archive data signing Lesson 10 - Troubleshooting ๏‚ง Set specific internal logging levels ๏‚ง Identify and solve common issues ๏‚ง Learn how to get community help with Splunk ๏‚ง Understand how to contact Splunk Support
  • 2. Splunk Education Services Splunk Education Tracks User: For all day-to-day Splunk users including customer support staff, developers, systems administrators and management. Administrator: For administrators of Splunk itself. (Administrators of other systems who will just be using Splunk should take the User track.) Architect: For architects who will be designing Splunk deployments, including architects on staff at customer deployments as well as partner professional services personnel. Developer: For developers who will integrate, customize and extend Splunk using its XML templates and advanced configuration bundling. Support Engineer: For Splunk OEM and channel partner support staff who will be providing first line support for Splunk. Tracks User Administrator Architect Developer Support Engineer Using Splunk โœ“ โœ“ โœ“ โœ“ โœ“ Searching and Reporting with Splunk โœ“ โœ“ โœ“ โœ“ Administrating Splunk โœ“ โœ“ โœ“ Advanced Splunk Administration โœ“ โœ“ โœ“ Architecting and Deploying Splunk โœ“ โœ“ Developing Apps with Splunk โœ“ โœ“ โœ“ Splunk Architect Certification Lab โœ“ Supporting Splunk โœ“ About Splunk Splunk is software that indexes, manages and enables you to search data from any application, server or network device in real time. Visit our website at www.splunk.com to download your own free copy. Splunk Inc. 250 Brannan San Francisco, CA 94107 866.GET.SPLUNK (866.438.7758) [email protected] [email protected]