Overview

This 18-hour course is designed for administrators who are responsible for getting data into Splunk Indexers. The course provides the fundamental knowledge of Splunk forwarders and methods to get remote data into Splunk indexers. It covers installation, configuration, management, monitoring, and troubleshooting of Splunk forwarders and Splunk Deployment Server components.

Skills Covered

  • Understand sourcetypes
  • Manage and deploy forwarders
  • Configure data inputs
  • Fire monitors
  • Network inputs (TCP/UDP)
  • Scripted inputs
  • HTTP inputs (via the HTTP Event Collector)
  • Customize the input phase parsing process
  • Define transformations to modify data before indexing
  • Define search time knowledge object configurations

Who Should Attend

Everyone can attend.

Course Curriculum

Prerequisites

To be successful, students should have a solid understanding of the following courses:

  • What Is Splunk?
  • Intro to Splunk
  • Using Fields
  • Introduction to Knowledge Objects
  • Creating Knowledge Objects
  • Creating Field Extractions

OR the following courses:

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2 (recommended)

Students should also have understand the following course:

  • Splunk Enterprise System Administration (recommended)

Download Syllabus

Course Modules

Request More Information