Purpose: Learn how to use Splunk effectively.
Audience: Anyone needing the skills to use Splunk effectively
Role: Software Developer, General user
Course Overview:
This 2-day Splunk training course is designed to demonstrate a functional use of Splunk. The course begins with a lesson on how to utilize Splunk to run basic searches. Next, it explores stats, tags, and even types and fundamentals of Splunk. The course concludes with a lesson on creating reports and dashboards.
Productivity Objectives:
After this course, you will be able to:
- Utilize Splunk to run searches
- Identify the fundamentals of a Splunk search
- Discover the stats command and its functions
- Create reports and dashboards
Course Benefits:
- Deepen your Splunk knowledge and become a power user.
- Master advanced search techniques for data exploration and analysis.
- Transform data into informative visualizations for clear communication.
- Automate tasks and streamline workflows with macros.
- Integrate Splunk with external systems for broader functionality.
- Optimize search performance for faster results and improved efficiency.
Course Outline:
Splunk – Getting Started
- Populating data
- Controlling Splunk
- Creating your first dashboard
Bringing in Data
- Splunk data sources
- Creating Indexes
- Buckets
- Log Files as data input
- Splunk events and fields
- Extracting new fields
Search Processing Language
- Anatomy of a search
- Time modifiers
- Filtering search results
- Functions and Commands
- Fields/Stats/Tags
- Search best practices
- Additional Search commands
Reporting, Alerts, and Search Optimization
- Data enrichment with Lookups
- Creating and scheduling reports
- Creating alerts
- Search and Report acceleration
- Scheduling options
Dynamic Dashboarding
- Creating effective dashboards
- Types of dashboards
- Creating a time range input
- Static real-time dashboard
Data Models and Pivots
- Creating a data model
- Creating a Pivot table
- Data model acceleration
- Rearranging your dashboard
Hands-On Labs:
These hands-on labs will equip you with advanced Splunk skills through the following modules:
Module I: Leveraging Advanced Search Techniques
- Master commands for geographic visualization (iplocation, geostats, geom) and data aggregation.
- Utilize advanced filtering and formatting (eval, search, where, filnull) for precise control and clear results.
Module II: Data Manipulation for Effective Visualizations
- Learn how to transform search results into informative charts, timecharts, and maps for impactful data presentation.
Module III: Unlocking Event Correlation and Transaction Analysis
- Identify transactions and group events using fields and time for uncovering complex insights.
Module IV: Optimizing Search Results with Knowledge Objects
- Understand naming conventions, permissions, and effectively manage saved searches, reports, and dashboards.
Module V: Mastering Field Management Techniques
- Extract data efficiently using field extractors.
- Create field aliases and calculated fields for enhanced searchability.
Module VI: Organizing Data with Tags and Event Types
- Implement tags and event types for efficient data organization and improved searchability.
Module VII: Automating Tasks with Macros
- Develop macros with arguments and variables to streamline repetitive tasks.
Module VIII: Integrating Splunk with External Systems
- Utilize workflow actions (GET, POST, Search) for data manipulation and seamless integration with external systems.
Module IX: Exploring Data Models and the CIM Add-On
- Grasp the relationship between data models and pivots.
- Leverage the CIM Add-On for data normalization.
Module X: Configuring Advanced Splunk Alerts
- Create proactive alerts with lookups, logging, indexing, and webhook actions for real-time monitoring.
Module XI: Optimizing Search Performance Strategies
- Implement report acceleration and summary indexing techniques for faster search results.
Note: Labs and exercises are integrated throughout the course to solidify your understanding and practical skills.
