Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Splunk Enterprise Admin 2023 (Hands-on Labs: Crash Course )
Rating: 4.7 out of 5(45 ratings)
2,896 students

Splunk Enterprise Admin 2023 (Hands-on Labs: Crash Course )

Hands-On Labs: Deploy and configure Splunk platform in a distributed environment (NEW! Nov 2022)
Last updated 12/2022
English
English [Auto],

What you'll learn

  • Set up a working Splunk environment in a distributed architecture design ( fast paced Practical Lab )
  • understand and deploy Splunk Universal Forwarders on Linux based Machines
  • understand and deploy Splunk Universal Forwarders on Windows Machine
  • Explore Splunk apps and the thriving Splunkbase community
  • Distributed Search architecture Discussion and Overview: Add search peers to the search head

Course content

1 section8 lectures1h 24m total length
  • Before we begin: Lab Overview3:10

    Configure universal forwarders on Linux and Windows to monitor files under the Volokh directory, set inputs.conf and outputs.conf, and add the indexer as a search peer.

  • LAB: Discuss and deploy the Universal Forwarder on Linux6:46

    Install the universal forwarder on a Linux system, create a Splunk user, set ownership under /opt, and start it via the CLI; no UI and no data forwarding yet.

  • LAB: Configure the UF for monitoring input and forward the logs to the Indexer18:15

    Configure the universal forwarder to monitor /var/log/secure* with inputs.conf, use host segment three, forward to the indexer on port 9997 via outputs.conf, and ensure Splunk ownership with a dedicated app.

  • LAB:Discuss & configure the Indexer for log receiving and the fishbucket concept16:16

    Configure the Splunk indexer to listen on 9997, forward logs from the universal forwarder, enable the index security index, and trigger re-ingestion by clearing the fish bucket.

  • LAB: Discuss and deploy the Universal Forwarder on a windows machine9:55

    Deploy the universal forwarder on Windows, forward logs to the Splunk indexer over port 9997, install the Windows add-on for parsing and field extraction, and enable search head access.

  • LAB: configure the Indexer and deploy Windows App on the UF and the Indexer18:59

    Configure and deploy a Windows index on the Splunk indexer, create and enable the Windows index, and install the Windows add-on from Splunk Base to enable log collection and parsing.

  • LAB: Discuss and deploy the Search Head as part of the distributed Architecture9:42

    Learn to configure a distributed Splunk search head by adding an indexer as a search peer, deploying via settings, and enabling quarantine for underperforming peers.

  • Bonus!1:19

Requirements

  • some background Splunk experience is highly Recommended
  • Understand basic networking concepts is highly recommended
  • Basic Linux experience helpful but not required
  • Install software in a Windows or Linux environment

Description

The best  hands-on labs crash course for learning Splunk, the leader in real-time monitoring, log management, and SIEM (security information and event management).


For a complete Course, please check out my other full deployment Admin certification Course!!


Your instructor is Saif Al-Shoker, a former SPLUNK  Architect Employee and a Splunk Certified core Consultant  and Architect with over 10 years of experience in the security domain, 5 years splunking and hold two master degrees.


This fast lab course, is a sample part which focuses on system administrator and data administrator learning content.

In this micro nugget course, we will go through deploying the Universal Forwarder on a Linux and Windows machines, configure the monitoring inputs, deploy windows app and forward the logs to the indexing tier, lastly I will discuss and configure the search head and add the search peer as part of the Splunk distributed architecture design.


Don't buy poor quality courses! This course is a free high quality that I will take you step by step to successfully deploy Splunk in a distributed architecture design, through engaging video tutorials and teach you everything you need to know to be a successful Splunk Administrator

I remember my first time when I started to learn Splunk, I didn’t know where to start and with all the information out there makes it even harder to grasp, so today I am putting my self in your shoes to help you conquer this complexity .so I have designed this free course specially for you to take you


Who this course is for:

  • Anyone who wants to get the Splunk Enterprise Certified Admin certificate ( Lab )
  • Individuals who are looking to have solid practical foundation in Splunk
  • Anyone who has been tasked with deploying a Splunk environment
  • Security professionals
  • Anyone wAnyone who wants to make a lot of money by boosting their resume with Splunk knowledge and experience is serious about learning Splunk