
Splunk Training: Operational Data Analytics with Splunk Courseware (WA2952)
This Splunk training course introduces the students to the Splunk Operational Data Analytics platform.
Publisher: Web Age Solutions
Benefits
- Splunk components
- Data sources
- SPL
- Forwarders
- Data visualizations
Outline
- Splunk Introduction
- Splunk Defined
- Splunk Products
- The Magic Quadrant for Security Information and Event Management (SIEM)
- Splunk Editions
- Deployment Options
- Common Components
- Splunk Admin Dashboard (Web UI)
- Events
- Data Indexing
- Distributed Splunk Indexing and Searching
- Architecture for a Multi-Tier Splunk Enterprise Deployment
- Summary
- Splunk Data Sources
- Data Source Types
- The Source Types Automatically Recognized by Splunk
- The “Pre-trained” Source Types
- Windows ® Data Sources
- Data Indexing
- Web UI for Adding Data to Indexer
- Web UI: Adding Data Flow for Local File Upload
- Web UI: Add Data for Monitoring
- Automatic Recognition of Data Source
- Where is My Uploaded File?
- Custom Event Format
- Summary
- Searching and Reporting with Splunk
- Data Searching
- The Search Processing Language (SPL)
- Searching and Reporting Activities
- The Search Page
- Core Search Concepts
- Search Command Auto-Completion
- The Search Basics
- Search Command Categories
- Command Examples
- More Examples of Search Commands
- Statistical Commands
- Statistical and Time Functions
- From SQL to SPL – the Translation Table
- Visual Aids for Building Search Queries
- Visualizations
- Save Your Searches as Dashboards
- The Delete Operation
- How Do I Delete My Data?
- Summary
- Splunk Forwarders
- Flavors of Splunk Forwarders
- Forwarder Comparison Table (Abridged)
- The Splunk Forwarder Diagram
- Splunk Universal Forwarder (UF) Supported OSes
- UF Functions
- What UF Cannot Do
- Summary
- Lab Exercises
- Learning the Lab Environment
- Local File Upload
- Local File Upload Project
- TCP Port Real-time Monitoring
- Using Search and Reporting App
- Querying for Insights
- Understanding Universal Forwarders (For Review Only)
- Using Universal Forwarders Project (For Review Only)
- Data Visualization
- Dealing with Missing Timestamps
- The Delete Operation
- vi Bare Essentials (Optional)
Required Prerequisites
- General knowledge of programming using SQL as well as some experience working in UNIX environments (e.g., running shell commands, etc.).
License
Length: 2
days | $150.00 per copy