
Master Splunk Cloud admin basics, including cloud overview, authentication, index management, configuration files, data forwarding, inputs, parsing, app management, and exam details.
Explore the Splunk cloud overview, cloud service, topology, and admin tasks, and compare it to Splunk enterprise, focusing on hosted management, access limitations, and scalable indexing.
Learn how to deploy Splunk Cloud with universal, intermediate, and heavy forwarders, manage on-prem parsing and masking, and navigate data ingestion and licensing options.
Explore Splunk cloud overview: a fully managed service with deployment, maintenance, and security handled by Splunk, plus vetted add-ons and platform differences (Victoria vs classic).
Provide an overview of Splunk Cloud, including data inputs from forwarders and cloud sources, SSL or TLS, and admin tasks across indexes, parsing, knowledge objects, apps, and users.
Launch a free Splunk cloud trial, install on premise Splunk, and configure it as a forwarder (universal forwarder) to send data to the cloud, while exploring the cloud monitor console.
Install Splunk Enterprise on premise by downloading the Linux rpm for CentOS eight, install the universal forwarder for cloud logging, use a non-root user, accept license, and start service.
Configure native, LDAP, and SAML users with roles to enforce authentication and authorization in Splunk Cloud; no CLI admin and use a read-only LDAP over the DMZ for integration.
Learn to manage Splunk Cloud users and authentication, including creating native accounts, assigning rules, password management, LDAP and authentication methods, and caution around delete permissions.
Learn how to integrate ldap with splunk cloud for authentication using a read-only domain controller in a dmz, including bind credentials, user and group mapping, and cloud versus on-prem configurations.
Learn how to create and tailor rules in Splunk Cloud, including default and admin rules, token authentication, inheritance, capabilities, index permissions, and restrictions.
Learn to define and create cloud indexes, monitor indexing, and manage retention across three availability zones, using per-data-type indexes and event versus metric indexes to optimize resources.
Learn how to create and configure a Splunk Cloud index, choosing name and type (event or metric), set retention, max size, and searchable time for optimal data management.
Explore Splunk cloud platform dynamic data storage options: Splunk archive, self storage via AWS S3, or no storage; archive enables easy restore to searchable indexes with retention policy guidance.
Explore how Splunk configuration files govern inputs, indexes, and file precedence across enterprise and cloud, focusing on .conf with stanza and attribute structure, and CLI or API options.
Explore the Splunk directory structure across Linux and Windows, including Splunk home, bin, and apps, and learn best practices to edit configurations in the local directory rather than default files.
Learn how Splunk configuration files are organized and prioritized across global and app contexts, including inputs, outputs, props, and source types, with guidance to consult the official documentation.
Explore index-time processing in splunk, including input, parsing, field extraction, enrichment, and masking, then licensing and indexing, with emphasis on configuration file priority across system local, apps, and defaults.
Explore how Splunk applies configuration at search time across user context and app context, using a precedence from user local directories to default, global, and system directories.
Learn how to get data into the Splunk Cloud using forwarders, HTTP, event collector, and API; deploy universal, heavy, or intermediate forwarders with SSL, guided by best practices.
Explore universal forwarder basics, remote deployment via deployment server, and forwarding on premise data to Splunk Cloud or an intermediate forwarder, with best practices for parsing and cloud credentials.
Install and configure the Splunk universal forwarder on Windows, download credentials, and set up inputs and outputs to feed data into Splunk Cloud, following deployment server guidance.
Install the Linux universal forwarder and the cloud app, download credentials, and configure inputs to monitor files so Splunk Cloud can receive data and display logs.
Learn how to forward on-premises network data to Splunk Cloud using syslog servers and universal forwarders, with best practices for heavy forwarders and monitoring in the cloud.
Explore forwarder management with the deployment server to distribute apps and configurations to universal forwarders via server classes, targeting Windows and Linux groups.
Learn how to configure Splunk deployment server and universal forwarders, including deployment.conf setup, server class creation, and distributing outputs to indexers across a distributed environment.
Set up and manage Splunk forwarders with deployment server, installing linux and windows add-ons, and publishing cloud apps via server classes to linux and windows clients.
Configure the deployment server to centrally distribute Splunk apps to forwarders. Map clients to server classes, push universal forwarders, and apply cloud and Windows and Linux add-ons.
Learn how Splunk monitors file and directory inputs in real time, configuring input settings with source type, host, and index, and handling compressed and various text formats.
Review inputs.conf, its monitor stanzas, and the attributes used to define file and directory monitoring in Splunk. Use wildcards and three dots for recursive matching across var/log and secure logs.
Configure Splunk input options to control data ingestion, using follow tail and filters such as white/black lists and regex. Set host values with host segment or host regex for attribution.
Configure the deployment server to monitor files and directories across Windows hosts, create or reuse a server class, and set the source type and index for clients.
Discover how the fish bucket lets Splunk monitor input files and directories, track head and tail pointers, and configure stanza with mandatory and optional fields.
Explore network inputs in Splunk, including TCP, UDP, scripted inputs, Windows inputs, and the REST API for pushing requests and ingesting data.
Explore network inputs in Splunk Cloud, noting no tcp/udp inputs; send syslog via universal forwarder or heavy forwarder, or configure on-prem udp inputs on port 514 for Cisco.
Explore scripted inputs that use shell, batch, PowerShell, or Python scripts to collect diagnostics (CPU, memory, processes, network) and ingest them into Splunk, with guidance on script placement and scheduling.
Learn to collect Windows inputs with Splunk using the universal forwarder, including event logs, performance metrics, registry and Active Directory changes, and deploy configurations via the deployment server.
Learn how the http event collector ingests data over https from devices that can't install udf, using token-based authentication, no forwarders, and ip-based access lists for cloud and on-prem Splunk.
Explains why cloud Splunk blocks tcp/udp inputs and shows configuring a syslog server (syslog-ng) and universal forwarder for parsing, filtering, and offline log retention to prevent data loss.
Fine-tuning inputs in the Splunk Cloud Certified Admin course guides you through default input processing, source type selection, and character set encoding to ensure data is correctly sent to Splunk.
Are you ready to unlock the power of Splunk Cloud and become a skilled Splunk Cloud Administrator? Join this comprehensive course and gain the knowledge and hands-on experience needed to effectively manage and optimize your organization's log analysis and monitoring infrastructure.
In today's data-driven world, businesses rely on real-time insights to make informed decisions and stay ahead of the competition. Splunk Cloud, a leading cloud-based log analysis and monitoring platform, empowers organizations to harness the power of their machine-generated data for security, operational intelligence, and business analytics.
In this course, you'll embark on a journey to become a proficient Splunk Cloud Administrator. Starting from the fundamentals, you'll learn how to set up, configure, and maintain Splunk Cloud environments, ensuring maximum performance and scalability. Through practical demonstrations and hands-on exercises, you'll gain proficiency in key administrative tasks, such as managing users and roles, securing data, and troubleshooting common issues.
Course Highlights:
Introduction to Splunk Cloud
Index Management
User and Role Management
Splunk Configuration Files
Getting Data in Cloud
Forwarder Management
Monitor Inputs
Network and Other Inputs
Fine-tuning Inputs
Parsing Phase and Data Preview
Manipulating Raw Data
Installing and Managing Apps
By the end of this course, you'll possess the knowledge and practical skills to confidently administer Splunk Cloud environments, enabling you to drive efficient log analysis, real-time monitoring, and actionable insights within your organization.
Whether you're an IT professional, system administrator, or aspiring Splunk Cloud expert, this course equips you with the essential skills to excel in managing and optimizing Splunk Cloud deployments. Enroll now and embark on your journey towards becoming a proficient Splunk Cloud Administrator!
Note: Prior experience with Splunk or log analysis is beneficial but not required. The course welcomes beginners and provides a solid foundation before diving into advanced topics.