Creating Dashboards with Splunk

Splunk Training Provider Authorised Learning Partner Australia

The Creating Dashboards with Splunk course is designed for power users who want to create fast and efficient views that include customized charts, drilldowns, advanced behaviors and visualizations.


Major topics include using tokens, global searches, event handlers, dynamic drilldowns and simple XML extensions for JavaScript and CSS.

Units : 2
Duration : 9 hours over 2 days
Time : 9:00 am – 1:30 pm AEST (GMT +10)

*Course discounts apply for Splunk Partners. Please use the currency convertor above to check for course pricing in your local currency.

Creating Dashboards with Splunk

The instructor very knowledgeable and was able to provide useful examples during the course..

Participant, Splunk Enterprise System Administration

Creating Dashboards with Splunk
Creating Dashboards with Splunk - Course Topics
  • Simple XML

  • Tokens

  • Global Searches

  • Dynamic Drilldowns

  • Event Handlers

  • Simple XML Extensions

Class Format

Instructor-led lecture with labs. Delivered via virtual classroom or at your site

Course Prerequisites
Related Certifications
Creating Dashboards with Splunk - Audience

Anyone whose role includes analysing and presenting complex data sets. Previous attendees have included Consultants, Business Intelligence/Business Analysts, Data Scientists and Application Developers.

  • Working Knowledge of XML

  • Some experience with HTML, CSS, and JavaScript (recommended)

After completing Creating Dashboards with Splunk course you will be able to
  • Understand 3 types of Splunk apps

  • Know what an app consists off

  • Create a simple XML app

  • Use custom drilldowns and forms to enhance dashboards

  • Brand & Package your own Splunk app

Creating Dashboards with Splunk
Creating Dashboards with Splunk - Course Objectives

Module 1 – Creating a Prototype

  • Define simple syntax for views

  • Use best practices for creating views

  • Identify transforming commands

  • Troubleshoot views

Module 2 – Using Forms

  • Explain how tokens work

  • Use tokens with form inputs

  • Define types of token filters

  • Create cascading inputs

Module 3 - Improving Performance

  • Identify ways to improve dashboard performance

  • Use the tstats command

  • Use global searches

  • Accelerate data models

Module 4 – Customising Dashboards

  • Customize chart and panel properties

  • Set panel refresh and delay times

  • Disable search access features

  • Define event annotations

Module5 – Using Drilldowns

  • Define types of drilldowns

  • Identify predefined tokens

  • Create dynamic drilldowns

Module 6 – Adding Visualisations and Behaviors

  • Identify types of event handlers

  • Describe event actions

  • Create contextual drilldowns

  • Use simple XML extensions

  • Define Splunk Custom Visualizations

Splunk Course Schedules and Timezones

Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones.

Dates and times displayed for each course are relative to Australian Eastern Time (AET).

AM Marked Splunk Courses

AM marked courses start at AET 9:00am and finish at AET 1:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas;

  • UTC+10 including Australia (East Coast)

  • UCT+11/+12 including New Zealand and the Pacific Islands

  • UTC-8 including USA (West Coast), Canada (West Coast)

  • UTC-7 including USA (Mid West)

PM Marked Splunk Courses

PM marked courses start at AET  2:00pm and finish at AET 6:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas;

  • UTC+9 including Japan, Korea

  • UTC+8 including Australia (West Coast), Singapore, Hong Kong, China, Philippines, Brunei, Thailand

  • UTC +5/+6 including India and Sri Lanka

Creating Dashboards with Splunk - Upcoming Courses