Cluster Administration

The Cluster Administration course is for an experienced Splunk Enterprise administrator who is new to Splunk Clusters. The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment.


The Cluster Administration course covers installation, configuration, management and monitoring of Splunk clusters.

While Splunk Clusters are supported in Windows environments, the class lab environment is running on Linux instances only.

Units : 3
Duration : 13.5 hours over 3 days
Time : 9:00 am – 1:30 pm AEST (GMT +10)

*Course discounts apply for Splunk Partners.

This course was very interactive . Logging into Splunk and showing how to do it, giving examples and showing the ins and outs of ES actually makes a huge difference. Well done to the instructor.

Participant, Using Splunk Enterprise Security

Course Topics
  • Large-scale Splunk Deployment Overview

  • Single-site (high-availability) Indexer Cluster

  • Multisite (disaster-recovery) Indexer Cluster

  • Indexer Cluster Management and Administration

  • Indexer Discovery Forwarder Configuration

  • Search Head Cluster

  • Search Head Cluster Management and Administration

  • KV Store Collection and Lookup Management

Class Format

Instructor-led lecture with labs. Delivered via virtual classroom or at your site

Course Prerequisites

Splunk System Administration (Required)

Splunk Data Administration (Required)

Troubleshooting Splunk

Working LINUX Knowledge

3 Months of hands-on Splunk Administration experience

Related Certifications

Anyone involved in the design, deployment and administration of Splunk within organisations. Previous attendees have included Consultants, IT Administrators, Pre-Sales Engineers and Solution Architects.

After completing this course you will be able to
  • Configure Splunk for High Availability and Disaster Recovery

  • Set up search head clustering

  • Configure and manage clusters

  • Identify troubles within a clustered environment

  • Add and remove cluster nodes

Course Objectives

Module 1 – Large-scale Splunk Deployment Overview

  • Factors that affecting deployment design

  • Splunk cluster overview

  • License Master

Module 2 – Single-site Indexer Cluster

  • Splunk single-site indexer cluster configuration

  • Optional single-site indexer cluster configurations

Module 3 – Multisite Indexer Cluster

  • Splunk multi-site indexer cluster overview

  • Multi-site indexer cluster configuration

  • Optional multi-site indexer cluster configurations

  • Cluster migration and upgrade considerations

Module 4 – Indexer Cluster Management and Administration

  • Indexer cluster storage utilization options

  • Peer offline and decommission

  • Master app bundles

  • Monitoring Console for indexer cluster environment

Module 5 – Forwarder Management

  • Indexer discovery

  • Optional indexer discovery configurations

Module 6 – Search Head Cluster

  • Splunk search head cluster overview

  • Search head cluster configuration

Module 7 – Search Head Cluster Management and Administration

  • Search head cluster deployer

  • Captaincy transfer

  • Search head member addition and decommissioning

  • Monitoring Console for Search Head Cluster

Module 8 – KV Store Collection and Lookup Management

  • KV Store collection in Splunk clusters

  • KV Store monitoring with Monitoring Console

Course Schedules and Timezones

Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones.

Dates and times displayed for each course are relative to Australian Eastern Time (AET).

AM Marked Courses

AM marked courses start at AET 9:00am and finish at AET 1:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas;

  • UTC+10 including Australia (East Coast)

  • UCT+11/+12 including New Zealand and the Pacific Islands

  • UTC-8 including USA (West Coast), Canada (West Coast)

  • UTC-7 including USA (Mid West)

PM Marked Courses

PM marked courses start at AET  2:00pm and finish at AET 6:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas;

  • UTC+9 including Japan, Korea

  • UTC+8 including Australia (West Coast), Singapore, Hong Kong, China, Philippines, Brunei, Thailand

  • UTC +5/+6 including India and Sri Lanka

Upcoming Courses


Copyright 2020/2021