
Master the basics of Splunk, search over data, utilize fields, create alerts, employ lookups, and transform data with statistical functions to prep for the core user certification.
Learn how data sprawl makes Splunk essential as a log aggregator and visualizer to monitor logs, detect anomalies like impossible travel, and support security and capacity use cases.
Elevate basic computer users into educated Splunk practitioners through this masterclass, becoming go-to experts for security, infrastructure, or management roles, including security operations center analysts, admins, and architects.
Discover why Splunk remains an eight-year leader in the 2021 Gartner Magic Quadrant for security information and event management, with on-premises and cloud options, mature tooling, and the spl language.
Explore the three core Splunk server roles—forwarder, indexer, and search head—along with universal and heavy forwarders, ingest data, indexing, and SPL-driven search, plus dashboards and alerts.
Explore Splunk architectures by examining the three core components (forwarder, indexer, and search head) and how deployment server, cluster master, and license master support high availability and disaster recovery.
Download and install Splunk Enterprise via the free 60‑day trial, log in with admin credentials, and launch. Start ingesting data and building dashboards for a functional single deployment.
Configure and scale a splunk stack by assigning server roles (forwarder, indexer) and ensuring sufficient ram, cpu, and disk space; manage dashboards and reports in the searching and reporting app.
Upload data into Splunk using the web interface, inspect pretrained or custom source types, and adjust timestamps and field extraction to ensure accurate event ingestion.
Upload and configure data in a Splunk lab by importing three data sources—access_combined_ip, linux_secure_ip, and db_audit_csv—setting hosts, main index, and source types.
Master the Splunk search window, using the search processing language with time range filtering, pipes, wildcards, booleans, and the search assistant for efficient data analysis.
Learn to search with Splunk's search processing language, create efficient queries to detect failed ssh logins, and analyze results with time ranges, port filtering, and shared saved searches.
Master Splunk field basics to filter searches with key value pairs, utilize the fields sidebar and selected fields, understand discovery, time ranges, and efficient indexing for rapid, accurate insights.
Explore Splunk's search processing language and learn how the left-to-right pipeline, pipe separators, and commands like chart, stats, eval, and fields shape results into a table.
Learn to use common Splunk commands—fields, table, rename, and dedupe—to extract unique user sessions with successful purchases and tailor reports for marketing campaigns.
Explore transforming commands in Splunk—top, rare, and stats—to aggregate data, apply limits and by clauses, rename fields, and use count, sum, and distinct count.
Derive insights from data by transforming commands in Splunk, creating practical reports for sales, security, and IT, using top, rare, stats, and rename operations.
Create and share reports and dashboards to answer data questions. Build a 403 by client IP report and a product sales dashboard with a column chart visualization.
Create pivot dashboards in Splunk to visualize items added to cart and referrer domains, filter by cart events, switch to a line chart, and save to a dashboard.
Enrich searches with lookups, linking static data from lookup tables or definitions to events. Automate enrichment using automatic lookups and lookup tables to add fields like product name and price.
Enrich data by implementing lookups and automatic lookups to replace product IDs with human readable product names and prices, then visualize total revenue by product name on a dashboard.
Explore scheduled reports and alerts in Splunk, distinguishing saved searches, scheduled searches, and condition-driven actions with examples like failed login attempts and off-hours email deliveries.
Learn how to set permissions for knowledge objects in Splunk, controlling read and edit access to reports, dashboards, alerts, and macros via app, owner, or run-as options.
Learn how Splunk alerts trigger on predefined criteria and route actions via emails, scripts, or webhooks to Slack or Teams, and compare scheduled interval alerts to real-time alerting for efficiency.
Create visibility with alerts by building a search for 500-level http statuses and configure a scheduled alert with throttling, email or log actions, and token-based dynamic content.
Develop a real-time alert in Splunk that notifies when more than zero failed admin logins occur within one minute, using the underscore audit internal index and throttling by host.
Finish the Splunk Core User Masterclass by encouraging practice with test exams and labs, and announce the upcoming Splunk Power User Masterclass and the course catalog.
Description
Hello and welcome to the Splunk Core Certified User Masterclass! Jump into Splunk with us and learn how to search, monitor, and examine machine-generated data through an intuitive, web-style interface. With over 7 years of professional Splunk experience, instructor Josh will provide you a high-level breakdown of everything you need to know to pass the Splunk Core Certified User certification! Never worked with Splunk before? Don't worry, we've got you covered! This masterclass was made for those with zero Splunk experience, and even minimal computer knowledge. Josh will walk you through every step of the way, providing insight, explanation, and best practices to ensure you're learning the industry standard for Splunk. By the end of this course you will feel confident and reassured to pass the Splunk Certified Core user exam!
What is Included?
#1. Eight hands-on labs that reinforce content learned as you progress.
#2. Visual explainers, highlights and motion graphics to help you better grasp the concepts.
#3. Professional, high quality video and audio ensuring a smooth and effective delivery.
#4. Corresponding Lab summaries with guided steps.
#5. Course E-Slides and Practice Exams.
So what are you waiting for? Join us today and pass that Splunk Core Certified User certification exam!