
Learn Splunk deployment overview, including forwarders, indexers, and search heads, data flow from inputs through parsing and indexing to searching, and single to distributed deployments plus cli and monitoring tasks.
Learn to manage Splunk licenses, including enterprise trial, free, enterprise, and forwarder licenses, and monitor license alerts to prevent violations and possible shutdowns.
Log in to settings licensing, switch from the 60-day trial license group to an enterprise license, install the license file or pasted XML, then restart and log back in.
Explore Splunk applications, including what an app is, the difference between apps and add-ons, installation methods (GUI or CLI), and how default and non-default apps and permissions are managed.
Transfer the unix and linux add-on from Splunk base to an EC2 instance via scp, then extract and place it in Etsy apps directory and restart Splunk to load it.
Explore how Splunk configuration files govern system behavior, focusing on inputs, outputs, and props conf, and learn global, app, and user precedence plus using the B tool for troubleshooting.
Explore Splunk configuration files by examining default and local directories, copying stanzas to local, and editing inputs. Use btool to verify inputs, props, and outputs with practical examples.
Learn how Splunk indexes store events in hot, warm, cold, and frozen buckets, with setup steps for new indexes, sizing, retention, and access controls using Splunk web and CLI.
Learn how Splunk stores and manages indexes in Splunk DB, create a Linux index, and monitor using CLI or GUI, plus health checks in the monitoring console.
Learn to configure and manage Splunk indexes via indexes.conf, including bucket sizes, retention, and path settings, monitor health in the monitoring console, and safely move, delete, or thaw buckets.
Learn how to manage Splunk user roles, assign permissions, and create custom roles, including admin, power user, user, and the can delete role, with Ldap and api options.
Explore how to manage users and roles in Splunk Enterprise, create custom roles, assign capabilities, restrict index access, and configure app launch and editor settings in a hands-on demo.
Configure forwarding in Splunk by deploying universal forwarders to remote servers, sending data to an indexer over port 9997, and validating inputs.conf and outputs.conf configurations.
Demonstrates forwarding Linux logs to a central Splunk server using a universal forwarder, including enabling receiving on port 9997, configuring outputs, and starting the forwarder.
Explore distributed search across forwarders, indexers, and search heads, including search peers and license manager roles, and learn to generate and analyze a Splunk diag to troubleshoot across your environment.
Generate a Splunk diag for a single instance, customize included data and metadata, download the tar.gz, and review logs to diagnose health and prepare for support.
Splunk Administration: Launch Your Career as a Splunk Administrator
Welcome to Ableversity's Splunk Administration Course, where power users transform into skilled administrators. This comprehensive course is developed under the expert oversight of Michael Bentley, "The Splunk Doctor," one of the most respected Splunkers in the world, ensuring you receive training that meets the highest industry standards.
Why This Course Stands Apart
This is where you transition from using Splunk to administering it at the enterprise level. Learning from industry leaders with real-world deployment experience, you'll gain the critical knowledge and practical skills needed to manage Splunk environments confidently. Our instructors bring insights that only come from years of hands-on administration in complex enterprise settings.
What You'll Master
Through 17 comprehensive lessons combining theory and hands-on demonstrations, you'll learn to deploy, configure, and manage every critical aspect of a Splunk environment. From deployment architecture to user management, you'll develop the complete skill set required for professional Splunk administration.
Master essential administrative concepts including Splunk deployment strategies, license management, application configuration, configuration files, index creation and management, user roles and authentication, data forwarding and receiving, Splunk diagnostics, and distributed search architecture.
Your Path to Certification
This course is specifically designed for the Splunk Enterprise Administration Certification track and follows the official blueprint for the Splunk Enterprise Admin Certification exam offered by PearsonVUE. Our students consistently report passing their certification exams after completing this course, validating the professional-grade training you'll receive.
Please note: The prerequisite certification for the Splunk Enterprise Admin exam is Splunk Core Certified Power User.
Join Our Community
Learning doesn't stop when the videos end. Connect with us on LinkedIn, X, and Slack, or visit our website for additional resources and support. We're committed to your success and encourage you to reach out with any questions or concerns. We're here to help you succeed.
Enroll today and launch your Splunk administration career with the guidance of true industry leaders.