
Discover what Splunk is, why it serves as a SIEM and big data analytics platform, and how this course helps you pass the Splunk Core Certified Power User exam.
Understand Splunk's core components: forwarders, indexers, and search heads—and explore deployment options from standalone to multi-instance, including clustering and deployment servers for management.
Download the Splunk GUI installer from Splunk.com, start a free 60-day Splunk Enterprise trial for Windows 64-bit, run the GUI installer, set credentials, and access Splunk Web at loopback 8000.
Download the free 60-day trial of Splunk Enterprise for macOS, install via the wizard to the default /Applications path, then log in to Splunk Web on port 8000.
Upload practice data to Splunk using Cisco WSA and Unix add-ons, assign source types (access_combined, linux_secure), create indices (web, security, cisco), and run a search across all time to verify.
Explore the Splunk data pipeline, from input and parsing to license tracking and indexing, and learn to configure inputs, data preview, and local log collection.
Demonstrate data preview and creating inputs in Splunk, comparing csv versus log formats and adjusting source types. Configure local event log and Windows host inputs for live search and analysis.
Explore the difference between apps and add-ons in Splunk, including gui-driven apps on the search head and background technology add-ons (TAs) that onboard and optimize data.
Master the basics of searching in Splunk by navigating the search bar, using time pickers and search modes, and exploring fields, events, and operators to build effective queries.
Learn what knowledge objects are, how to create and manage them, and how permissions and naming conventions enable collaboration across apps in Splunk.
Demonstrate Splunk knowledge objects by creating an alert for excessive failed logins from a Russian IP, then configure permissions, throttling, and email alerts.
Define splunk fields as key-value pairs with case-sensitive names and case-insensitive values. Learn to search by one or multiple fields and use not operators to filter results.
Learn how Splunk's search processing language uses color-coded syntax—orange modifiers, blue commands, green arguments, and pink functions—while mastering table, rename, fields, dedupe, and sort.
Demonstrate building SPLs and using basic commands—table, rename, fields, dedupe, and sort—while exploring top values and totals in search and reporting.
Explore transforming commands in Splunk, including top, rare, and stats, and learn how they convert event values into numerical data for analysis, with smart mode behavior and practical demos.
Explore transforming commands in Splunk, including top values and rare values, to analyze fields like category ID and refer domain. Apply stats, counts, and table formatting to reveal insights.
Explore how the transaction command groups related events into end-to-end conversations, using max span, max pause, starts with, and ends with, and contrast it with faster, resource-friendly stats command.
Learn to use the transaction command in Splunk to group events by session, set max duration, and study web and security data for user actions and 404s.
Master data manipulation with eval, where, and search to create calculated fields, filter results, and convert epoch time to readable dates, while understanding field overwriting and command placement.
Explore advanced field handling in Splunk, including extracting new fields with regex and delimiters, and using rex and erex to generate or craft extractions.
Learn to access Splunk’s field extractor in three ways, then create fields using the GUI, regular expressions rex and erex, and validate results with previews and permissions.
Explore lookups in Splunk: define static data files, perform data enrichment by querying lookups, and create or upload lookups using input and output commands.
learn to create and query lookups in splunk by uploading a csv, defining a lookup, and using input lookup with where filters to enrich searches and analyze product data.
Visualize data in Splunk with tables, single values, gauges, bar, line charts, pie charts, maps, and learn to use stats, chart, and timechart with stacking, overlay, trellis, and multi-series.
Explore how to create and customize visualizations in Splunk, including time charts, bar and pie charts, dashboards, and quick reports, with practical examples of actions, purchases, and failed logins.
Explore visualizations in Splunk as we cover iplocation, geostats, addtotals, and trendline to enhance panel dashboards with location insights, maps, totals, and moving averages for your analytics.
Explore building and refining Splunk dashboards with time charts, trend lines and SMA moving averages, then visualize geo data with IP location, geo stats, and cluster maps.
Explore how to create, save, and manage reports and drilldowns in Splunk, including scheduling, naming best practices, token usage, and exporting dashboards to pdf for a home dashboard view.
Learn how to build a home dashboard in Splunk, create panels, pass tokens, add inputs, perform searches with time tokens, generate reports, and configure drilldowns and pdf exports.
Create and manage alerts in Splunk by configuring scheduled or real-time searches, setting trigger conditions, throttling, and actions like logging or emailing, with severity and permissions considered.
Explore tagging events and using event types to color-code and organize data in search and reporting, with practical demos of creating tags, applying colors, and analyzing login events.
Discover how to create and use macros in Splunk to save time on recurring searches, pass arguments, and manage macros via settings.
Learn to create and manage Splunk search macros, including examples like salesmade, top5, and fileinfo, and how to use arguments and expand the underlying search.
Learn to create and configure Splunk workflow actions, including GET, POST, and search actions, with an IP whois lookup demo to save time and verify results.
Learn how to normalize data with field aliases and calculated fields using eval, manage Splunk buckets from hot to frozen, and use the job inspector for troubleshooting.
Create field aliases for IP data across web, security, and Cisco as source_ip; build megs from bytes and inspect job performance and bucket states with dbinspect.
Discover how Splunk data models organize datasets into hierarchical structures to accelerate searches, using tstats, field aliases, and pivot tools for faster, normalized data analysis.
Explore and manage Splunk data models, view and edit CIM-compliant data models, and use pivots and spl to search, count, and visualize data from web and authentication models.
Map your data to the common information model to enable CIM compliant searches with consistent field names, using 22 pre-configured data models, data normalization, and the CIM add-on builder.
Log into Splunk, install the CIM app, and map web data to the CIM Web data model using the add-on builder, field aliases, and data model mappings.
Hello and welcome to the course. This is the #1 place to learn by watching instructor lead demonstrations on Splunk. Don’t take another course that is bogged down with long lectures and endless PowerPoint slides. Take one that covers the majority of the course via recorded demonstrations and is built for visual learners!
This course is designed to take someone who has never heard of Splunk and provide them with the knowledge they need to pass the Splunk Core Certified Power User exam!
Is it hard to find a streamlined education road map for Splunks old Fundamentals 1 and 2 concepts? This course is it!
Learn by watching demonstrations for over 75% of the course!
Download your own data and practice on your own instance of Splunk.
Learn over 25 commands through many examples!
Gain confidence in how to craft strong searches, build visualizations, and understand the key components of Splunk.
This course will cover all the key topics you need to pass the exam!
I hope you continue to take what you have learned here and move on to learning more advanced topics that Splunk has to offer!
See you in the course and good luck on the exam!