
Introduction of the course and what the prereqs are
Exploring the job opportunities that are NEEDED for Splunk Engineers/Administrators
Introduction on what Splunk is and how it works
We are going to discuss the important Splunk ports, what they are used for and how important they are for your deployment
We are going to cover the different deployments types that a Splunk Administrator can deploy
We are going to talk about how Splunk licensing works and how it's important for a deployment
Introduction to the AWS Cloud Environment and how to get started
Learn how to create a Windows EC2 Instance. We are going to install a Splunk Forwarder later
Learn how to create a Linux EC2 Instance. We are going to install a Splunk Forwarder later
Learn how to create a Linux EC2 Instance. We are going to install a Splunk Enterprise later
Learn how to install Splunk Enterprise on the EC2 Instance
Learn how to configure Indexes on Splunk Enterprise
Learn how to configure receiving ports on Splunk Enterprise
Learn how to install a Splunk Forwarder on a Windows Host
Learn how to install a Splunk Forwarder on a Linux Host
Learn how to configure Forwarder Management. Centrally configure Forwarder configurations for Windows and Splunk Hosts
Troubleshooting steps if you are running into issues with Forwarder Management
Going to cover basic searches, how time is your friend, different modes for a search and cover what fields are
Indepth guide on Fields within Splunk and how to create new Fields
Going to cover how time is your friend and cover the best practices involved
Going to cover the Table Command
Going to cover the Rename Command
Going to cover the Dedup Command
Going to cover the Sort Command
Going to go over the Top Command
Going to go over the Rare Command
Going to go over the Stats Command
Here are all of the searches that I've made in many production environments
Introduction of visualizations with basic searches
Going to go over the Chart Command
Going to go over the TimeChart Command
Learn how to create simple dashboards
Learn how to import pre-existing dashboards into Splunk
Discuss what Splunk Apps are, where to obtain them and what are the two most important ones when first starting
If you are a beginner with Splunk or you are a novice, this course will go in-depth on the basic concepts for Splunk, how to configure it and configure multiple pieces to get it working.
Splunk is one of the industry standards for SIEM tools, centralized logging mechanisms, etc. Splunk is a very easy and verse tool. You can configure simple or complex searches/dashboards. I wanted to create this course because there is A LOT of information out there. However, it’s either all scattered or there are no detailed explanations on how to configure Splunk. I want to equip you the key components of Splunk, how to configure searches and centrally manage forwarders to pull data into Splunk.
We will cover how to setup and configure an AWS environment. Everything is moving into the cloud and it's important to get familiar with a cloud environment that's used heavily within the cooperate world and government sectors
I've left a resources section what contains all of the searches that I've made within a production environment. No one else is doing this! I wanted to share this with you so that you can understand what searches to make and, more importantly, make you look like a ROCKSTAR