top of page

Search Results

Search this site

102 results found

  • Advanced Dashboards and Visualizations | INGENIQ

    Splunk Education, Training and Professional Services Provider Advanced Dashboards and Visualizations with Splunk 8.1 Summary This one-day course is designed for advanced users who want to create SplunkJS dashboards and Splunk Custom Visualizations. It focuses on creating dashboards, adding inputs, using event handlers and creating Splunk Custom Visualizations using JavaScript and XML. Description SplunkJS Dashboards Tokens Using Event Handlers Custom Visualizations Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Enjoyable presenter and easy to understand for an intermediate Splunk user pursuing Admin certification. Thanks from Massachusetts! Participant, Splunk Fundamentals 2 Splunk Credit Value: 50 Duration: 4.5 hours Time: 11am – 3.30 pm AEST Objectives Module 1 – SplunkJS Dashboards Identify view types Create a SplunkJS dashboard Define view properties, methods and events List types of search managers Module 2 – Using Tokens Use tokens in SplunkJS Define Splunk’s token models Describe how to get, set, and change tokens Create a SplunkJS form Module 3 – Using Event Handlers Identify types of event handlers Define event handler syntax Define drilldown properties Create an event handler Module 4 – Creating Custom Visualizations Define the custom visualization primary files Add custom visualizations to views Create a custom visualization Define security best practices Prerequisites To be successful, students should have a solid understanding of the following courses: Splunk Fundamentals 1 Splunk Fundamentals 2 OR the following single-subject courses: What Is Splunk? Intro to Splunk Using Fields Visualizations Data Models Introduction to Dashboards Dynamic Dashboards Students should also have the following skills: Using a terminal editor (vi,nano, etc) Editing JavaScript, XML, CSS and HTML Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses start at AEDT 12:00pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West)

  • Splunk Users Track | INGENIQ

    Splunk Education, Training and Professional Services Provider Users The User Learning path takes you from investigative keyword searches to creating rich reports and visualisations to becoming a Splunk search ninja! Notice : The following courses; Using Splunk, Searching and Reporting with Splunk, Creating Splunk Knowledge Objects, and Splunk Infrastructure Overview are now replaced with Splunk Fundamentals 1 and Splunk Fundamentals 2. User Track Courses Splunk Fundamentals 1 Splunk Fundamentals 2 Splunk Fundamentals 3 Creating Dashboards with Splunk Advanced Searching and Reporting Splunk for Analytics and Data Science Splunk Infrastructure Overview Advanced Dashboards and Visualisations One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration

  • Training Terms and Conditions | INGENIQ

    Splunk Education, Training and Professional Services Provider Training Terms and Conditions Courses can be booked by phoning Ingeniq, sending an email or via www.ingeniq.com.au and are covered by the following terms and conditions. Ingeniq® is a registered trademark and wholly owned business division of Digital Networks Australia Pty Ltd. Digital Networks Australia Pty Ltd trades as Ingeniq® using the trademark and as such all legal requirements and agreements including contracts, notices, insurances, taxes and terms of trade are matters for Bluechip Infotech. Application of Terms These booking terms and conditions alone will form part of the agreement between the parties and will apply to any booking received or attendance at any course that is facilitated by Ingeniq, regardless of the process leading to a booking or the method of payment used in respect of such services. Acceptance of any purchase order will not constitute acceptance of any terms or conditions which may be attached to, or incorporated in, a purchase order. Supply of Services Ingeniq, a Bluechip Infotech agrees to supply services (“Services”) to a purchaser, attendee, student or course recipient (“Client”, “You” or “Your”) on these standard terms and conditions (“Terms”). Information on training events, courses and services are correct at the time of publication but are subject to change without notice. Ingeniq reserves the right to change course content, schedules and information at any time. Ingeniq assumes no responsibility for any and all expenses incurred due to course cancellations. Should a course be cancelled by Ingeniq, the paid seat for the course is transferable. Purchase Orders Any changes to these Terms for the supply Services must be approved in writing by Ingeniq. Only these Terms form part of the agreement between the parties and as such exclude any other terms and conditions which may be attached to, or incorporated in, a purchase order. Acceptance of a purchase order by Ingeniq will not constitute acceptance of any such terms or conditions. Taxes and GST Prices quoted for Services are in Australian Dollars and may exclude GST. The total amount payable to Ingeniq includes taxes, duties and government charges imposed or levied in Australia in connection with the supply of the Services. The client is required to pay any GST owed in connection with the supply and Ingeniq will issue a valid tax invoice where GST is to be collected. Course Bookings and Payment Course bookings can be made with Ingeniq over the phone, via email or via the Ingeniq website. Bookings are made on a “first-come, first-served” basis. Should the course or event be fully booked applicants will be placed on a waiting list. Payment can be made by Credit Card, EFT, Cheque, Purchase Order (for Credit Clients only) or vendor training credits (with vendor approval). Course bookings are not confirmed until payment is received. Unless a credit account is agreed or vendor training credits approved payment is due at time of booking. Training included as part of a product/software order is considered paid at the time invoice for the product/software order is paid. Payment for a course registration must be received no less than three business days before course commencement. Splunk Training Credits Vendor training credits (purchased directly through Splunk) can be applied to Ingeniq training courses. Splunk Credits are non-refundable and expire 12 months after date of purchase. Booking requests for Splunk Training Credits must be submitted in writing and approval from Vendor has be given before the student can be registered. Course Attendance Courses start and finish at the times scheduled unless specified otherwise. Ingeniq reserves the right to decline admission courses for late arrivals. Course prerequisites as specified in the course outlines must be met prior to attendance. Should a student fail to attend a course, 100% of course fees are payable and non-refundable. Course Conditions Training Credits are non-refundable and expire 12 months after date of purchase. . Refunds are NOT available for bookings if a student cancels the booking within three business days before course commencement. “Private Courses” are courses arranged for an organisation where attendees are typically restricted to approved registrants of that organisation. Private courses can be conducted on-site at the organisations premises, on-site at third party premises or virtually. Private Courses require payment at time of booking. Ingeniq makes no warranty in relation to the Services other than as contained in these Terms or as prescribed by a law which cannot be excluded or as otherwise published or made known to the Client. Cancellations and Transfers Public Courses Notification of booking cancellation must be received in writing 3 or more working days prior to course commencement date. Substitutions: Substitution of attendees are permitted provided that the substitution request is received in writing 3 or more working days priors prior to course commencement. Refunds will not be issued to students who fail to attend training. Private Courses All requests to cancel or change private course dates must be made in writing to and acknowledged by Ingeniq no less than 10 business days prior to the commencement date of the course. Requests for Private Course cancellation and date change received by Ingeniq less than 10 business days prior to the start of the course will incur a fee of 50% of the total course price, Requests for Private Course cancellations and date change requests received less than 5 business days prior to the start of the course will incur a fee of 80% of the total course price. Intellectual Property Material or courseware unless agreed otherwise in writing is provided is copyright and will remain the property of Ingeniq (or the relevant vendor, where such rights are owned by a vendor) and cannot be copied, reproduced or distributed without the express permission of Ingeniq or the relevant vendor. All material provided or shown is for the sole use of the course attendee and any usage rights are only conferred on payment of all charges payable in connection with those rights. Confidentiality Ingeniq and the Client agree to keep at all times as strictly confidential any Confidential Information that is disclosed or provided by one party to the other. In this clause, “Confidential Information” means information in any form but does not include information that is required to be shared by Ingeniq with a vendor to obtain courseware, accreditation or licensing rights, or is already in the public domain at the time that it is disclosed or becomes part of the public domain, otherwise than as a result of an unauthorised disclosure by Ingeniq or the Client. Privacy All information that Ingeniq collects in connection with your purchases or bookings will be treated in accordance with the Ingeniq Privacy Policy. Ingeniq will collect, use and disclose your personal information for the purpose of enabling you to enrol in a course, and to allow Ingeniq to deliver the course and related Products and Services to you. Ingeniq uses your information to: Communicate with you about your course, events, activities, products, services and opportunities available to you; Disclose your personal information to overseas vendors. Such vendors are those relevant to the course, products or courseware you have requested from Ingeniq; Carry out and record your details in internal administrative matters; and Fulfil any vendor requirements regarding your attendance for certification, planning, administration, policy development, program evaluation and other related or lawful purposes. As a division of Digital Networks Australia Pty Ltd refer to the Trading Terms and Conditions for all other general terms and conditions

  • Advanced Searching and Reporting Training Legacy Course Information delivered by INGENIQ

    Advanced Searching and Reporting Training Legacy Course Information delivered by INGENIQ Advanced Searching and Reporting - Legacy Course Information The Advanced Searching and Reporting course focuses on more advanced search and reporting commands. Scenario-based examples and hands-on challenges enable users to create robust searches, reports, and charts. Students are coached step by step through complex searches to produce final results. Major topics include optimizing searches, additional charting commands and functions, formatting and calculating results, correlating events, and using combined searches and sub-searches. This Advanced Searching and Reporting Splunk Courses have been replaced by shorter Splunk single-subject course modules , this page have been retained to assist customers. To see which courses have replaced Advanced Searching and Reporting and book the equivalent course click here Single-subject to Multi-subject course mapping. Alternatively contact one of our Training Consultants on 1300 245 802 or email sales@ingeniq.com.au Extremely proficient at controlling the pace of training. Great explanation of answers & not just reading the content. Very knowledgeable about all content. Looking forward to completing the rest of the of the class. Highly recommended. Participant, Splunk Enterprise Data Administration Advanced Searching and Reporting - Course Topics Using Search Efficiently More Search Tuning Manipulating and Filtering Data Working with Multivalue Fields Using Advanced Transactions Working with Time Combining Searches Using Subsearches Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites Splunk Fundamentals 1 Splunk Fundamentals 2 Splunk Fundamentals 3 Highly recommend 6 months experience with the Splunk search language Related Certifications Splunk Core Certified Advanced Power User Splunk Core Certified Consultant Advanced Searching and Reporting - Audience Anyone within a technical role who needs to utilise more complex searches or reports or are looking to become Splunk certified. Previous attendees have included Consultants, IT Administrators, Data Scientists, Security and Risk Professionals and Solution Architects. After completing Advanced Searching and Reporting course you will be able to Extend your basic search language knowledge Understand and use sub-searches Create advanced visualisations using extended search language Identify events before or after events Use advanced lookups Understand and be able to use the DB Connect App Advanced Searching and Reporting - Course Objectives Module 1 – Using Search Efficiently Review search architecture Understand how the components of a bucket (.tsidx an djournal.gz files) are used How bloom filters are used to improve search speed Describe the parts of a search string Understand the use of centralized vs. distributable commands Create better searches Module 2 – More Search Tuning Understand how segmenters are used in Splunk Use lispy to reduce the number of events read from disk Module 3 - Manipulating and Filtering Data Divide search results into different groups, based on values in a specified field, using the bin command Regroup fields of search results using untable and xyseries Create a template for performing additional processing on a set of related fields using foreach Module 4 - Working with Multivalue Fields Use multivalue eval functions to analyze and format data Use the makemv command to convert a single value into a multivalue field Use the mvexpand command to create separate events for each value in a multivalue field Module 5 - Using Advanced Transactions Find events logged before or after a particular event occurs Compare complete vs. incomplete transactions Analyze Transactions Module 6 – Working with Time Use time modifiers Search for events using custom time ranges and time windows Display and use using relative dates Use custom time ranges in multiple subsearches Module 7 – Combining Searches Use the append and appendcols commands (and know the differences) Use join and union (and when not to use them) Module 8 – Using Subsearches Use subsearches to provide filtering and other information to the main search Know when NOT to use subsearches Troubleshoot subsearches Module 9– Some Extra Tips Describe the use of regular expressions Provide some guidance on using lookups Provide miscellaneous optimization tips Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West)

  • Splunk Enterprise Administrator Track | INGENIQ

    Splunk Education, Training and Professional Services Provider Splunk Enterprise Administrators Whether you're responsible for a single Splunk instance or a massive distributed deployment, our Administrator curriculum teaches you the concepts, tasks, and best practices to keep your Splunk installation happy, healthy, and growing. Splunk Enterprise Administrators Track Courses Splunk Fundamentals 1 Splunk Fundamentals 2 Splunk Enterprise System Administration Splunk Enterprise Data Administration Troubleshooting Splunk Enterprise Splunk Enterprise Cluster Administration Implementing Splunk Smart Store Splunk Workload Management Working with Metrics in Splunk One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration

  • Working with Time - Splunk Education Single Subject Course Training

    Working with Time - Splunk Education Single Subject Course Training. Working with Time The Splunk Education single-subject course module, Working with Time is for power users who want to become experts at using time in searches. Topics will focus on searching and formatting time in addition to using time commands and working with time zones. Splunk Credit Value : 50 Duration : 3 hours Time : 9:00 am - 12:00 pm AEST Please use the currency convertor above to check for course pricing in your local currency. The instructor was very responsive to questions and queries both private and Communal.. Final module collaborative lab walkthrough on screen was particularly helpful. Participant, Splunk Fundamentals 2 Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Working with Time - Course Topics Searching with Time Formatting Time Comparing Index Time versus Search Time Using Time Commands Working with Time Zones Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge: Intro to Splunk Using Fields Visualizations Working with Time - Audience Search Experts and Knowledge Managers Working with Time - Course Objectives Topic 1 – Searching with Time Understand the_time field and timestamps View and interact with the event Timeline Use the earliest and latest time modifiers Use the bin command with the _time field Topic 2 – Formatting Time Use various date and time eval functions to format time Topic 3 - Using Time Commands Use the timechart command Use the timewrap command Topic 4 – Working with Time Zones Understand how time and timezones are represented in your data Determine the time zone of your server Use strftime to correct timezones in results Splunk Course Schedules and Timezones Splunk Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Working with Time - Upcoming Schedule We don’t have any products to show here right now.

  • Splunk Education Single Subject Course Training

    Splunk Education Single Subject Course Training. Ingeniq is the Authorised Splunk Training Provider for Australia and New Zealand and is certified to deliver the complete range of Splunk courses and offer both Instructor led public and dedicated virtual and face-to-face courses. Splunk Education - Single Subject Courses Ingeniq is the Splunk Training Provider and Authorised Learning Partner for Australia and New Zealand and is certified to deliver the complete range of Splunk courses and modules and offers both Instructor led public and dedicated virtual and face-to-face courses. Splunk Education single-subject Instructor led courses are smaller portions of Splunk training courses and take approx. 3 hours. Splunk Education single-subject training courses contribute to Splunk certifications. Unsure about which single-subject course to take? Our Education Consultants can help - call us or email at sales@ingeniq.com.au and we'll be in touch. Download the Splunk Education Student Handbook to learn about the latest updates in Splunk Training. Call us on 1300 245 802 What is Splunk? This Splunk training course introduces students to what machine data is and how Splunk can leverage operational intelligence to investigate and respond to incidents in their organizations. Visit Splunk Website Intro to Splunk This Splunk training course teaches students how to use Splunk to create reports and dashboards and explore events using Splunk's Search Processing Language. Students will learn the basics of Splunk's architecture, user roles, and how to navigate the Splunk Web interface to create robust searches, reports, visualizations, and dashboards Visit Splunk Website Using Fields This Splunk training course is for power users who want to learn about fields and how to use fields in searches. Topics will focus on explaining the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields. The last topic will introduce how fields from other data sources can be used to enrich search results. Read More Intro to Knowledge Objects This Splunk training course teaches students about how different types of knowledge objects to extract additional insights from their data. Students will learn the basics of how to create knowledge objects, define their settings, edit, and manage existing knowledge objects. Visit Splunk Website Creating Knowledge Objects This Splunk training course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros, and calculated fields. Read More Creating Field Extractions This Splunk training course is for knowledge managers who want to learn about field extraction and the Field Extractor (FX) utility. Topics will cover when certain fields are extracted and how to use the FX to create regex and delimited field extractions. Read More Enriching Data with Lookups This Splunk training course is for knowledge managers who want to use lookups to enrich their search environment. Topics will introduce lookup types and cover how to upload and define lookups, create automatic lookups, and use advanced lookup options. Additionally, students will learn how to verify lookup contents in search and review lookup best practices. Read More Data Models This Splunk training course is for knowledge managers who want to learn how to create and accelerate data models. Topics will cover datasets, designing data models, using the Pivot editor, and accelerating data models. Read More Introduction to Dashboards This Splunk training course is designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on dashboard creation, including prototyping, the dashboard definition, layout types, adding visualizations, and dynamic coloring. Read More Dynamic Dashboards This Splunk training course module is designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on creating inputs, chain searches, event annotations, and improving dashboard performance. Read More Creating Maps This Splunk training Course helps you understand more about Choropleth maps. These maps have specific data and component requirements. A search uses the data and components to generate a choropleth map. Read More Scheduling Reports and Alerts This Splunk training course teaches students how to use scheduled reports and alerts to automate processes in their organization. Students will create, manage, and schedule reports and alerts, and use alert actions to further respond to incidents as they occur. Visit Splunk Website Visualisations This Splunk training course teaches students how to use scheduled reports and alerts to automate processes in their organization. Students will create, manage, and schedule reports and alerts, and use alert actions to further respond to incidents as they occur. Visit Splunk Website Working with Time This Splunk training course is for power users who want to become experts at using time in searches. Topics will focus on searching and formatting time in addition to using time commands and working with time zones. Read More Statistical Processing This Splunk training course is for power users who want to identify and use transforming commands and eval functions to calculate statistics on their data. Topics will cover data series types, primary transforming commands, mathematical and statistical eval functions, using eval as a function, and the rename and sort commands. Read More Comparing Values This Splunk training course is for power users who want to learn how to compare field values using eval functions and eval expressions. Topics will focus on using the comparison and conditional functions of the eval command, and using eval expressions with the field format and where commands. Read More Result Modification This Splunk training course is for power users who want to use commands to manipulate output and normalize data. Topics will focus on specific commands for manipulating fields and field values, modifying result sets, and managing missing data. Additionally, students will learn how to use specific eval command functions to normalize fields and field values across multiple data sources. Read More Leveraging Lookups and Subsearches This Splunk training course is designed for power users who want to learn how to use lookups and sub searches to enrich their results. Topics will focus on lookup commands and explore how to use sub searches to correlate and filter data from multiple sources. Read More Correlation Analysis This Splunk training course is for power users who want to learn how to calculate co-occurrence between fields and analyze data from multiple datasets. Topics will focus on the transaction, append, appendcols, union, and join commands. Read More Search Under the Hood This Splunk training course gives students additional insight into how Splunk processes searches. Students will learn about Splunk architecture, how components of a search are broken down and distributed across the pipeline, and how to troubleshoot searches when results are not returning as expected. Visit Splunk Website Multivalue Fields This Splunk training course is for power users who want to become experts on searching and manipulating multivalue data. Topics will focus on using multivalue eval functions and multivalue commands to create, evaluate, and analyze multivalue data. Read More Search Optimisation This Splunk training course is for power users who want to improve search performance. Topics will cover how search modes affect performance, how to create an efficient basic search, how to accelerate reports and data models, and how to use the tstats command to quickly query data. Read More One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration

  • Splunk Fundamentals 3 Training Legacy Course Information delivered by INGENIQ

    Splunk Fundamentals 3 Training Legacy Course Information delivered by INGENIQ Splunk Fundamentals 3 - Legacy Course Information The Splunk Fundamentals 3 course focuses on additional search commands as well as advanced use of knowledge objects. Major topics include advanced statistics and eval commands, advanced lookup topics, advanced alert actions, using regex and erex to extract fields, using spath to work with self-referencing data, creating nested macros and macros with event types, and accelerating reports and data models. This Fundamentals 3 Splunk Courses have been replaced by shorter Splunk single-subject course modules , this page have been retained to assist customers. To see which courses have replaced Splunk Fundamentals 3 and book the equivalent course click here Single-subject to Multi-subject course mapping. Alternatively contact one of our Training Consultants on 1300 245 802 or email sales@ingeniq.com.au Excellent Trainer, Have had the same instructor twice now & he is one of the best i have had. Thank you! Participant, Splunk Fundamentals 3 Splunk Fundamentals 3 - Course Topics Advanced Statistical Commands Advanced eval Commands Advanced Lookups Alert Actions Advanced Field Creation and Management Working with self-Describing Data and Files Advanced Macros Using Acceleration Options Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites Splunk Fundamentals 1 Splunk Fundamentals 2 Related Certifications Splunk Core Certified Advanced Power User Splunk Core Certified Consultant Splunk Fundamentals 3 - Audience Anyone whose role requires them to create complex search queries, advanced data models and reports with Splunk who have limited exposure to regular expressions. Previous attendees have included Consultants, IT Administrators and Business Intelligence/Business Analysts. After completing Splunk Fundamentals 3 course you will be able to Learn about and use KV store collections and scripted lookups in search and alerts. Inline extractions best practices using regex Working with structured data sources eg JSON and XML and table formatted events. Learn how and when to use report acceleration and summary indexing Learn how to seriously improve performance using tstats and data model acceleration. Splunk Fundamentals 3 - Course Objectives Module 1: Exploring Statistical Commands Performing statistical analysis with functions of the stat command Using fieldsummary Using appendpipe Using eventstats Using streamstats Module 2: Exploring eval Command Functions Using conversion functions Using data and time functions Using string functions Using comparison and conditional functions Using informational functions Using statistical functions Using mathematical functions Using cryptographic functions Module 3: Exploring Lookups Including and excluding events based on lookup values Using KV Store lookups Using external lookups Using geospatial lookups Using database lookups Understanding best practices for lookups Module 4: Exploring Alerts Referencing lookups in alerts Outputting alert results to a lookup Logging and indexing searchable alert events Using a webhook alert action Module 5: Advanced Field Creation and Management Using regex Using the erex command Using the rex command Identifying regex best practices Module 6: Working with Self-Describing Data and Files Using the spath command Using the eval command with the spath function Extracting fields from table-formatted events with multikv Module 7: Advanced Search Macros Using nested search Macros Previewing search macros before executing Using Tags and event types in search macros Module 8: Using Acceleration Options: Reports and Summary Indexing Using report acceleration Using Summary indexing Module 9: Using Acceleration Options: Data Models and tsidx Files Exploring data models using datamodel command Using data model acceleration Working with tsidx files using the tstats command Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West)

  • Splunk Enterprise Certified Administrator Splunk Certification | INGENIQ

    Splunk Enterprise Certified Administrator Splunk Certification | INGENIQ Splunk Enterprise Certified Administrator As a part of Splunk Certification, a Splunk Enterprise Certified Admin manages various components of Splunk Enterprise on a daily basis, including license management, indexers and search heads, configuration, monitoring, and getting data into Splunk. This certification demonstrates an individual’s ability to support the day-to-day administration and health of a Splunk Enterprise environment. The prerequisite courses listed below are highly recommended, but not required for candidates to register for the Splunk certification exam. All candidates seeking Splunk Enterprise Certified Architect or Splunk Certified Developer must complete Splunk Enterprise Certified Admin as a prerequisite certification. Learning Path Paid Training Paid Cert Exam Cert Exam - Splunk Core Certfied Power User Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Splunk Enterprise System Administration Splunk Enterprise Data Administration Cert Exam - Splunk Enterprise Certified Admin Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration

  • Splunk Certifications & Training | Ingeniq

    Ingeniq delivers official Splunk training and guided certification paths to help learners build skills and prepare for Splunk certifications effectively. Your Path to Splunk Certification Starts Here. Train with Australia’s authorised Splunk training provider — live instructors, hands-on labs, and certification-aligned learning. Start your Splunk journey with Ingeniq today. View Course Dates Explore Learning Paths ● Authorised Splunk Training Provider Since 2010 ● Thousands Trained Across Australia & New Zealand Plan Your Splunk Certification Speak with an Ingeniq expert about your certification goals — for individuals or teams. Full Name* Work Email* Company / Organisation* Course for: Notes: Send Enquiry Our team will contact you within one business day Why Choose Ingeniq for Splunk Certification Training Ingeniq is an authorised Splunk training provider delivering official, up-to-date courses trusted across ANZ. Our certified instructors help learners build practical skills, gain real-world confidence, and prepare effectively for Splunk certification. Why people choose Ingeniq: Authorised Splunk Training Provider Access official course content aligned with Splunk’s latest standards. Certified, Industry-Experienced Instructors Learn directly from practitioners who use Splunk in real environments. Hands-On, Lab-Driven Learning Build real capability with exercises that mirror production scenarios. Certification-Aligned Paths Follow structured journeys designed to get you exam-ready, faster. Up-to-Date Training Stay current with Splunk’s newest features, tools and best practices. Your Splunk Training Journey A simple overview of how Ingeniq prepares you for Splunk certification. Choose Your Product Path Pick courses or tailor with an Ingeniq expert. Enroll in a Course Use Splunk Credits or standard payment. Train Live With Experts Learn in instructor-led classes with labs. Get Exam-Ready Gain the skills needed for certification. Want a deeper look at the Splunk certification process? View Certification Training Guide How Splunk Certification Works Splunk certification validates your ability to work confidently in real Splunk environments. It proves your skills across search, administration, architecture, security or development — helping you grow your career and support your organisation. Ingeniq provides the official training that prepares you for the exam. All Splunk certification exams are delivered separately through Pearson VUE. What you can expect Official Splunk-aligned training Guidance from certified instructors Hands-on labs for real practice Certification exams via Pearson VUE Download the Splunk Certification Candidate Handbook for a full overview. Your Splunk Certification Options Core Certifications Admin & Architect Certifications Developer Certifications Security & ITSI Certifications Observability & Cybersecurity Certifications Splunk Core Certified User Build foundational skills in searching, fields, dashboards, alerts and reports. Ideal for beginners or anyone new to Splunk. View Learning Path Splunk Core Certified Power User Develop strong skills in search, reporting, knowledge objects, data models and CIM. Gain confidence working across Splunk Enterprise and Splunk Cloud. View Learning Path Splunk Core Certified Advanced Power User Master advanced search commands, complex dashboards, knowledge objects and data modelling for real-world use cases. View Learning Path Splunk Enterprise Certified Administrator Learn to configure and manage indexes, inputs, users, licensing, monitoring and system health across Splunk Enterprise environments. View Learning Path Splunk Enterprise Certified Architect Gain deep expertise in designing, deploying and troubleshooting distributed Splunk environments, including clustering and large-scale architectures. View Learning Path Splunk Cloud Certified Administrator Administer Splunk Cloud environments including data inputs, forwarder configuration, user management and basic troubleshooting. View Learning Path Splunk ITSI Certified Administrator Deploy and configure ITSI including service modelling, glass tables, notable events and deep dives to monitor critical services. View Learning Path Splunk Core Certified Consultant Expert-level certification covering large-scale deployments, multi-tier architectures, clustering and Splunk Deployment Methodology. View Learning Path Splunk Enterprise Security Certified Administrator Configure, manage and optimise Splunk Enterprise Security including correlation searches, threat intelligence, risk scoring and event processing. View Learning Path Splunk Core Certified Consultant Expert-level certification covering large-scale deployments, multi-tier architectures, clustering and Splunk Deployment Methodology. View Learning Path Splunk O11y Cloud Certified Metrics User Build foundational skills in monitoring and troubleshooting using Splunk Observability Cloud. Learn to collect metrics, configure the OpenTelemetry Collector, create visualizations, and set up alerts for real-time insights. Ideal for DevOps, SRE, and observability practitioners. TBA Splunk Certified Cybersecurity Defense Analyst Develop the skills to detect, analyze, and respond to cyber threats using Splunk Enterprise Security. Covers threat detection, investigation techniques, and security operations workflows. Ideal for SOC analysts and cybersecurity professionals. TBA Splunk Certified Cybersecurity Defense Engineer Advance your expertise in building and optimizing security operations in Splunk. Focus on detection engineering, automation (SOAR), and system optimization for scalable SOC environments. Ideal for security engineers and advanced SOC roles. TBA Which Certification Path Is Right for You? Choose a path based on your role and how you use Splunk. If you're unsure, Ingeniq experts can help you map the right certification journey. Core Track For beginners, analysts and anyone building foundational search, reporting and dashboard skills. Admin Track For IT teams, system administrators and platform owners managing Splunk environments. Security (ES) Track For SOC analysts, incident responders and security operations teams. SOAR Track For automation engineers and security orchestration teams building playbooks and workflows. ITSI Track For service owners and teams monitoring critical services using IT Service Intelligence. Security (ES) Track Coming soon — observability, O11y Cloud and APM-focused learning paths. Talk to a Training Advisor What Our Participants Say “The instructor was very knowledgeable and shared practical examples throughout the course." Participant, Splunk Enterprise System Administration — Australia Frequently Asked Questions (FAQs) Do you provide the certification exam? No. Splunk certification exams are delivered by Splunk through Pearson VUE. Ingeniq provides the official training that prepares you for those exams. Do your courses prepare me for Splunk certification? Yes. Our courses follow the official Splunk curriculum and align with the knowledge areas tested in Splunk certification exams. Can I take the exam without training? Yes, Splunk does not require training. However, most learners find that official courses significantly improve their exam readiness and confidence. Do you offer practice labs? Yes. All Ingeniq courses include hands-on lab environments so you can practice using Splunk in real-world scenarios. Start Your Splunk Certification Journey Talk to us about your Splunk certification goals, for individuals or teams. Choose your path, enrol in your courses, and build the skills you need to pass your Splunk certification with confidence View Course Dates Contact Us

  • Using Fields - Splunk Education Single Subject Course Training

    Using Fields - Splunk Education Single Subject Course Training. Using Fields The Splunk Education single-subject course module, Using Fields is a three-hour course and for power users who want to learn about fields and how to use fields in searches. Topics will focus on explaining the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields. The last topic will introduce how fields from other data sources can be used to enrich search results. Splunk Credit Value : 50 Duration : 3 hours Time : 9:00 am - 12:00 pm AEST Please use the currency convertor above to check for course pricing in your local currency. The instructor was very responsive to questions and queries both private and Communal.. Final module collaborative lab walkthrough on screen was particularly helpful. Participant, Splunk Fundamentals 2 Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Using Fields - Course Topics What are Fields What is Field Discovery Using Fields in Searches Comparing Temporary versus Persistent Fields Enriching Data Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge: How Splunk works Creating search queries Knowledge objects Using Fields - Audience Search Experts and Knowledge Managers Using Fields - Course Objectives Topic 1 – What are Fields? Understand fields and field auto-extraction Explore the Fields sidebar Add fields to the Selected Fields list Explore and generate reports from the Fields window Topic 2 – What is Field Discovery? Understand Field Discovery Explore search modes and their effect on search results Topic 3 - Using Fields in Searches Use fields correctly in basic searches Use fields with operators Use the rename command Use the fields command to improve search performance Topic 4 - Comparing Temporary versus Persistent Fields Differentiate between temporary and persistent fields Create temporary fields with the eval command Extract temporary fields with the erex and rex commands Topic 5 - Enriching Data Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data Splunk Course Schedules and Timezones Splunk Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Using Fields - Upcoming Schedule We don’t have any products to show here right now.

  • Administering SOAR Training delivered by INGENIQ

    Administering SOAR Training delivered by INGENIQ Administering Splunk SOAR The Administering SOAR (previously called Phantom) course prepares IT and security practitioners to install, configure and use a SOAR (Phantom) server in their environment and will prepare developers to attend the playbook development course. This 3.5 hour course prepares IT professionals to configure and manage SOAR Splunk Credit Value : 50 Duration : 3.5 hours over 1 day Time : 11:00 am - 2:30 pm AEST *Course discounts apply for Splunk Partners. Please use the currency convertor above to check for course pricing in your local currency. Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! The instructor very knowledgeable and was able to provide useful examples during the course.. Participant, Splunk Enterprise System Administration Administering SOAR - Course Topics SOAR concepts Initial configuration Apps and assets Configuring automation User management Ingesting data Customization and monitoring Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites To be successful, students must have a working understanding of these courses: Investigating Incidents with Splunk SOAR Related Certifications None Administering SOAR - Audience Anyone whose role includes deploying, or maintaining and configuring Splunk SOAR (Phantom). SOC Engineer, Security Architects, Threat Hunters & Responders. After completing Administering SOAR course you will be able to Install and configure SOAR (Phantom) Configure apps, assets, access control and manage playbooks Identify and onboard data into SOAR (Phantom) Work with containers, labels, artifacts, and tags Manage investigations with actions and playbooks Use workbooks and case management Module 1 – Initial Configuration Describe SOAR operating concepts Identify documentation and community resources SOAR & Splunk Architecture Product settings Access control Authentication settings Response settings Understanding roles Creating users Managing user access Module 2 – Apps, Assets and Playbooks Add and configure apps and assets Manage playbooks Ingesting Data Labels and tags Event settings Module 3 – Customisation and Monitoring Create custom severity levels Create custom status levels Add custom fields and CEF settings Create custom workbooks Run reports Use SOAR audit tools Monitor system health Administering SOAR - Course Objectives Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Administering SOAR (Phantom) - Upcoming Courses Administering Splunk SOAR : Starts August 13, 2026, 9:00am AET Price USD 500.00 Administering Splunk SOAR : Starts July 16, 2026, 9:00am AET Course Closed

bottom of page