Overview
This 18-hour course is designed for administrators who are responsible for getting data into Splunk Indexers. The course provides the fundamental knowledge of Splunk forwarders and methods to get remote data into Splunk indexers. It covers installation, configuration, management, monitoring, and troubleshooting of Splunk forwarders and Splunk Deployment Server components.
Skills Covered
- Understand sourcetypes
- Manage and deploy forwarders
- Configure data inputs
- Fire monitors
- Network inputs (TCP/UDP)
- Scripted inputs
- HTTP inputs (via the HTTP Event Collector)
- Customize the input phase parsing process
- Define transformations to modify data before indexing
- Define search time knowledge object configurations
Who Should Attend
Everyone can attend.
Course Curriculum
Prerequisites
To be successful, students should have a solid understanding of the following courses:
- What Is Splunk?
- Intro to Splunk
- Using Fields
- Introduction to Knowledge Objects
- Creating Knowledge Objects
- Creating Field Extractions
OR the following courses:
- Splunk Fundamentals 1
- Splunk Fundamentals 2 (recommended)
Students should also have understand the following course:
- Splunk Enterprise System Administration (recommended)
Course Modules
Exam & Certification
This course is not associated with any Certification.