Module 1:
Splunk Overview - Prerequisites and Installing Splunk Enterprise - Navigating Splunk Web - On-boarding data into Splunk Enterprise
Module 2:
Splunk knowledge objects Overview - Classify and group events - Define and Maintain Event types - Tags creation - Field extractions - Field Extractor - Search-time field extractions - Regular expression overview - Extract fields with search commands - Create custom fields at index time - Overview of Lookups - Usage of Field lookups to add info to your events - Configuring and customizing Lookups -- Saved Searches - Splunk CIM Overview and its correlation - Specify Cron Notation
Module 3:
Types of searches - Retrieving events - Specifying time ranges - Using subsearch - Creating statistical tables and charts - Grouping and correlating events - Predicting future events -Common search commands - Best practices in optimizing search - Functions for eval and stats command - Application of the following search commands by category - Correlation - Anomaly Detection - Reporting - Geographic - Prediction and Trending - Search and Sub-search commands - Time commands - Formats for converting strings into time-stamps - Understanding SPL syntax - Usage of Keywords and Boolean operators
Module 4:
Views Overview - Simple XML - Dashboards Overview - Functionalities - Panel creation and customization - Drilldowns - Employing Queries in Dashboards - Implementing JavaScript and CSS into Dashboards - Forms Creation - Form inputs definition - Macros Overview - Understanding of Data Models
Module 5:
Alerts Overview - Types of Alerts - Setup Alert actions - Scheduled Alert - Real time Alert - Custom conditional Alerts - Triggered Alerts - Alert Manager Usage - Alert Functionalities - Alert examples - Alerts via savedsearch.conf - Usage of Tokens - Troubleshooting Steps
Module 6:
Reporting Overview - Create and Edit Reports - Accelerate Report - Setup Scheduled Reports - Customize Report Formats - Report Functionalities - Report examples - Report via savedsearch.conf - Usage of Tokens - Troubleshooting Steps
Module 7:
Walk-through over Splunk Apps - Basic Understanding of Splunk App creation