Search Results
Search this site
102 results found
- Creating Dashboards with Splunk Training Legacy Course Information delivered by INGENIQ
Creating Dashboards with Splunk Training - Legacy Course Information delivered by INGENIQ Creating Dashboards with Splunk - Legacy Course Information The Creating Dashboards with Splunk course is designed for power users who want to create fast and efficient views that include customized charts, drilldowns, advanced behaviors and visualizations. Major topics include using tokens, global searches, event handlers, dynamic drilldowns and simple XML extensions for JavaScript and CSS. This Creating Dashboards with Splunk Courses have been replaced by shorter Splunk single-subject course modules , this page have been retained to assist customers. To see which courses have replaced Creating Dashboards with Splunk and book the equivalent course click here Single-subject to Multi-subject course mapping. Alternatively contact one of our Training Consultants on 1300 245 802 or email sales@ingeniq.com.au The instructor very knowledgeable and was able to provide useful examples during the course.. Participant, Splunk Enterprise System Administration Creating Dashboards with Splunk - Course Topics Simple XML Tokens Global Searches Dynamic Drilldowns Event Handlers Simple XML Extensions Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites Splunk Fundamentals 1 Splunk Fundamentals 2 Related Certifications Splunk Core Certified Advanced Power User Splunk Certified Developer Splunk Core Certified Consultant Creating Dashboards with Splunk - Audience Anyone whose role includes analysing and presenting complex data sets. Previous attendees have included Consultants, Business Intelligence/Business Analysts, Data Scientists and Application Developers. Skills Working Knowledge of XML Some experience with HTML, CSS, and JavaScript (recommended) After completing Creating Dashboards with Splunk course you will be able to Understand 3 types of Splunk apps Know what an app consists off Create a simple XML app Use custom drilldowns and forms to enhance dashboards Brand & Package your own Splunk app Creating Dashboards with Splunk - Course Objectives Module 1 – Creating a Prototype Define simple syntax for views Use best practices for creating views Identify transforming commands Troubleshoot views Module 2 – Using Forms Explain how tokens work Use tokens with form inputs Define types of token filters Create cascading inputs Module 3 - Improving Performance Identify ways to improve dashboard performance Use the tstats command Use global searches Accelerate data models Module 4 – Customising Dashboards Customize chart and panel properties Set panel refresh and delay times Disable search access features Define event annotations Module5 – Using Drilldowns Define types of drilldowns Identify predefined tokens Create dynamic drilldowns Module 6 – Adding Visualisations and Behaviors Identify types of event handlers Describe event actions Create contextual drilldowns Use simple XML extensions Define Splunk Custom Visualizations Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West)
- Splunk Core Certified User Splunk Certification | INGENIQ
Splunk Core Certified User Splunk Certification | INGENIQ Splunk Certification Exams Sample Certifcation exam questions (where available) are provided to give candidates a general idea of the formatting and type of questions for each of the exams. The test blueprints provide much more detailed information regarding exam content. Candidate performance on these questions in no way guarantees performance or passing marks on the certification exam(s). Available Splunk Certification exams Splunk Core Certified User Splunk Core Certified Power User Splunk Core Certified Advanced Power User Splunk Cloud Certified Admin Splunk Enterprise Certified Admin Splunk Enterprise Certified Architect Splunk Core Certified Consultant Splunk Certified Developer Splunk ES Certified Admin Splunk ITSI Certified Admin Splunk SOAR Certified Automation Developer Splunk Core Certified User What’s on the Exam This entry-level certification exam is a 57-minute, 60-question assessment which evaluates a candidate’s knowledge and skills to search, use fields, create alerts, use lookups, and create basic statistical reports and dashboards. Candidates can expect an additional 3 minutes to review the exam agreement, for a total seat time of 60 minutes. Splunk Core Certified User is a recommended entry-level certification track for all candidates. Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk ITSI Administrator | Splunk Training Pack delivered by INGENIQ
Splunk ITSI Administrator | Splunk Training Pack delivered by INGENIQ Splunk IT Service Intelligence Administrator Splunk Training Pack#5 Splunk ITSI Administrator Learn more, for less.. Ingeniq Splunk Training Packs are a collections of courses that when purchased together qualify for discounts of up to 25%. Splunk Training Packs apply to all Training Tracks and Certifications – in fact to any combination of courses purchased together from Ingeniq. Buy Splunk Training Pack#6 and you’ll sit all the courses you need to be certified as a Splunk IT Service Intelligence Admin. A Splunk IT Service Intelligence Certified Admin installs and configures Splunk’s app for IT Service Intelligence (ITSI), including ITSI architecture, deployment planning, service design and implementation, notable events and developing glass tables and deep dives. Call our Training Consultants now on 1300 245 802 or email sales@ingeniq.com.au to have this training pack tailored to you or your team' s requirements. Splunk Training Pack Courses Splunk Enterprise System Administration This virtual 9 hour course is designed for system administrators who are responsible for managing the Splunk Enterprise environment. The course provides fundamental knowledge of Splunk license manager, indexers and search heads. It covers configuration, management and monitoring core Splunk Enterprise components. Splunk Enterprise Data Administration This virtual 13.5 hour course is designed for system administrators who are responsible for getting data into Splunk Indexers. Implementing Splunk IT Service Intelligence This 4 day virtual course prepares consultants to install and configure Splunk’s app for IT Service Intelligence (ITSI). Students will learn to use ITSI to monitor mission-critical services. Topics include ITSI architecture, deployment planning, installation, service design and implementation, configuring entities, notable events, and developing glass tables and deep dives. Cert Exam - Splunk ITSI Administrator [USD 125] There are three ways to purchase a PearsonVUE registration voucher: Directly from PearsonVUE From Splunk (as an individual) From Splunk (as an account) Full instructions below. Addon & Save!! Splunk Fundamentals 1 This self-paced e-learning teaches you how to search and navigate in Splunk, use fields, get statistics from your data, create reports, dashboards, lookups, and alerts. It will also introduce you to Splunk’s datasets features and Pivot interface. his class is provided as free e-learning, to register click on this link to be directed to the Splunk training website: https://www.splunk.com/view/education/SP-CAAAAH9 Splunk Fundamentals 2 This course focuses on searching and reporting commands as well as on the creation of knowledge objects. Major topics include using transforming commands and visualizations, filtering and formatting results, correlating events, creating knowledge objects, using field aliases and calculated fields, creating tags and event types, using macros, creating workflow actions and data models, and normalising data with the Common Interface Model (CIM). Splunk Fundamentals 3 This course runs over 4 days and focuses on additional search commands as well as advanced use of knowledge objects. Major topics include advanced statistics and eval commands, advanced lookup topics, advanced alert actions, using regex and erex to extract fields, using spath to work with self-referencing data, creating nested macros and macros with event types, accelerating reports and data models. Advanced Searching and Reporting This 13.5 hour Splunk course focuses on more advanced search and reporting commands. Scenario-based examples and hands-on challenges enable users to create robust searches, reports, and charts. Students are coached step by step through complex searches to produce final results. Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk Education Single Subject Course Training
Splunk Education Single Subject Course Training. Ingeniq is the Authorised Splunk Training Provider for Australia and New Zealand and is certified to deliver the complete range of Splunk courses and offer both Instructor led public and dedicated virtual and face-to-face courses. Splunk Education - Single Subject Courses Splunk single-subject courses are available for registration. Splunk Education single-subject Instructor led courses are smaller portions of Splunk training courses and take approx. 3 hours. These will help you ramp your Splunk Learning quickly and efficiently and they are available as live Instructor-Led Training (ILT) or self-paced eLearning. Splunk Education single-subject training courses contribute to Splunk certifications. If you have started your Splunk training journey with the multi-subject courses and would like help defining the next steps our Education Consultants can help - call us or email at sales@ingeniq.com.au and we'll be in touch. Call us on 1300 245 802 To see the Single-subject to Multi-subject course mapping relationship, please refer to the Mapping column on the far right. Course Name Price Buy Now Learning Path Course Mapping What is Splunk? Free video eLearning Free eLearning Knowledge Manager , Search Expert Splunk Fundamentals 1 Intro to Splunk Free video eLearning Free eLearning Knowledge Manager , Search Expert Splunk Fundamentals 1 Scheduling Reports and Alerts Free video eLearning $500 or 1 credit Free eLearning , eLearning with Labs Search Expert Splunk Fundamentals 1 Using Fields $500 or 1 credit View Schedule Knowledge Manager , Search Expert Splunk Fundamentals 1 , Splunk Fundamentals 3 Visualisations Free video eLearning $500 or 1 credit Free eLearning , eLearning with Labs Search Expert Splunk Fundamentals 1 , Splunk Fundamentals 2 Working with Time $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 2 , Splunk Fundamentals 3 , Advanced Searching and Reporting Statistical Processing $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 2 Comparing Values $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 3 Result Modification $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 3 , Advanced Searching & Reporting Leveraging Lookups and Subsearches $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 3 , Advanced Searching & Reporting Correlation Analysis $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 2 , Advanced Searching & Reporting Search Under the Hood Free video eLearning $500 or 1 credit Free eLearning , eLearning with Labs Search Expert Splunk Fundamentals 2 , Splunk Fundamentals 3 , Advanced Searching & Reporting Multivalue Fields $500 or 1 credit View Schedule Search Expert Splunk Fundamentals 3 , Advanced Searching & Reporting Introduction to Knowledge Objects Free video eLearning Free eLearning Knowledge Manager Splunk Fundamentals 2 Creating Knowledge Objects $500 or 1 credit View Schedule Knowledge Manager Splunk Fundamentals 2 Creating Field Extractions $500 or 1 credit View Schedule Knowledge Manager Splunk Fundamentals 2 , Splunk Fundamentals 3 Enriching Data with Lookups $500 or 1 credit View Schedule Knowledge Manager Splunk Fundamentals 3 Data Models $500 or 1 credit View Schedule Knowledge Manager Splunk Fundamentals 2 , Splunk Fundamentals 3 Introduction to Dashboards $500 or 1 credit View Schedule Knowledge Manager Creating Dashboards Dynamic Dashboards $500 or 1 credit View Schedule Knowledge Manager Creating Dashboards Creating Maps $500 or 1 credit View Schedule Knowledge Manager Creating Dashboards Search Optimisation $500 or 1 credit View Schedule Knowledge Expert, Search Expert Splunk Fundamentals 3 Click on Read more to learn more about each Single Subject Course Training module and the course objectives. What is Splunk? This Splunk training course introduces students to what machine data is and how Splunk can leverage operational intelligence to investigate and respond to incidents in their organizations. Visit Splunk Website Intro to Splunk This Splunk training course teaches students how to use Splunk to create reports and dashboards and explore events using Splunk's Search Processing Language. Students will learn the basics of Splunk's architecture, user roles, and how to navigate the Splunk Web interface to create robust searches, reports, visualizations, and dashboards Visit Splunk Website Using Fields This Splunk training course is for power users who want to learn about fields and how to use fields in searches. Topics will focus on explaining the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields. The last topic will introduce how fields from other data sources can be used to enrich search results. Read More Intro to Knowledge Objects This Splunk training course teaches students about how different types of knowledge objects to extract additional insights from their data. Students will learn the basics of how to create knowledge objects, define their settings, edit, and manage existing knowledge objects. Visit Splunk Website Creating Knowledge Objects This Splunk training course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros, and calculated fields. Read More Creating Field Extractions This Splunk training course is for knowledge managers who want to learn about field extraction and the Field Extractor (FX) utility. Topics will cover when certain fields are extracted and how to use the FX to create regex and delimited field extractions. Read More Enriching Data with Lookups This Splunk training course is for knowledge managers who want to use lookups to enrich their search environment. Topics will introduce lookup types and cover how to upload and define lookups, create automatic lookups, and use advanced lookup options. Additionally, students will learn how to verify lookup contents in search and review lookup best practices. Read More Data Models This Splunk training course is for knowledge managers who want to learn how to create and accelerate data models. Topics will cover datasets, designing data models, using the Pivot editor, and accelerating data models. Read More Introduction to Dashboards This Splunk training course is designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on dashboard creation, including prototyping, the dashboard definition, layout types, adding visualizations, and dynamic coloring. Read More Dynamic Dashboards This Splunk training course module is designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on creating inputs, chain searches, event annotations, and improving dashboard performance. Read More Creating Maps This Splunk training Course helps you understand more about Choropleth maps. These maps have specific data and component requirements. A search uses the data and components to generate a choropleth map. Read More Scheduling Reports and Alerts This Splunk training course teaches students how to use scheduled reports and alerts to automate processes in their organization. Students will create, manage, and schedule reports and alerts, and use alert actions to further respond to incidents as they occur. Visit Splunk Website Visualisations This Splunk training course teaches students how to use scheduled reports and alerts to automate processes in their organization. Students will create, manage, and schedule reports and alerts, and use alert actions to further respond to incidents as they occur. Visit Splunk Website Working with Time This Splunk training course is for power users who want to become experts at using time in searches. Topics will focus on searching and formatting time in addition to using time commands and working with time zones. Read More Statistical Processing This Splunk training course is for power users who want to identify and use transforming commands and eval functions to calculate statistics on their data. Topics will cover data series types, primary transforming commands, mathematical and statistical eval functions, using eval as a function, and the rename and sort commands. Read More Comparing Values This Splunk training course is for power users who want to learn how to compare field values using eval functions and eval expressions. Topics will focus on using the comparison and conditional functions of the eval command, and using eval expressions with the field format and where commands. Read More Result Modification This Splunk training course is for power users who want to use commands to manipulate output and normalize data. Topics will focus on specific commands for manipulating fields and field values, modifying result sets, and managing missing data. Additionally, students will learn how to use specific eval command functions to normalize fields and field values across multiple data sources. Read More Leveraging Lookups and Subsearches This Splunk training course is designed for power users who want to learn how to use lookups and sub searches to enrich their results. Topics will focus on lookup commands and explore how to use sub searches to correlate and filter data from multiple sources. Read More Correlation Analysis This Splunk training course is for power users who want to learn how to calculate co-occurrence between fields and analyze data from multiple datasets. Topics will focus on the transaction, append, appendcols, union, and join commands. Read More Search Under the Hood This Splunk training course gives students additional insight into how Splunk processes searches. Students will learn about Splunk architecture, how components of a search are broken down and distributed across the pipeline, and how to troubleshoot searches when results are not returning as expected. Visit Splunk Website Multivalue Fields This Splunk training course is for power users who want to become experts on searching and manipulating multivalue data. Topics will focus on using multivalue eval functions and multivalue commands to create, evaluate, and analyze multivalue data. Read More Search Optimisation This Splunk training course is for power users who want to improve search performance. Topics will cover how search modes affect performance, how to create an efficient basic search, how to accelerate reports and data models, and how to use the tstats command to quickly query data. Read More One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk Enterprise Administrator | Splunk Training Pack delivered by INGENIQ
Splunk Enterprise Administrator | Splunk Training Pack delivered by INGENIQ Splunk Enterprise Administrator Splunk Training Pack#2 Splunk Enterprise Administrator Learn more, for less.. Ingeniq Splunk Training Packs are a collections of courses that when purchased together qualify for discounts of up to 25%. Splunk Training Packs apply to all Training Tracks and Certifications – in fact to any combination of courses purchased together from Ingeniq. Buy Splunk Training Pack#2 and you’ll sit all the courses you need to be certified as a Splunk Enterprise Administrator. A Splunk Enterprise Certified Admin manages various components of Splunk Enterprise on a daily basis, including license management, indexers and search heads, configuration, monitoring, and getting data into Splunk. Add-On any combination of courses to your training pack purchase and they’ll qualify for discounts too. Call our Training Consultants now on 1300 245 802 or email sales@ingeniq.com.au to have this training pack tailored to you or your team' s requirements. Splunk Training Pack Courses Splunk Enterprise System Administration This virtual 9 hour course is designed for system administrators who are responsible for managing the Splunk Enterprise environment. The course provides fundamental knowledge of Splunk license manager, indexers and search heads. It covers configuration, management and monitoring core Splunk Enterprise components. Splunk Enterprise Data Administration This virtual 13.5 hour course is designed for system administrators who are responsible for getting data into Splunk Indexers. Troubleshooting Splunk Enterprise This 2 day course is designed for Splunk administrators. It covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available on Splunk Enterprise. Cert Exam - Splunk Enterprise Admin [USD125] There are three ways to purchase a PearsonVUE registration voucher: Directly from PearsonVUE From Splunk (as an individual) From Splunk (as an account) Full instructions below. Addon & Save!! Splunk Fundamentals 2 This course focuses on searching and reporting commands as well as on the creation of knowledge objects. Major topics include using transforming commands and visualizations, filtering and formatting results, correlating events, creating knowledge objects, using field aliases and calculated fields, creating tags and event types, using macros, creating workflow actions and data models, and normalizing data with the Common Interface Model (CIM). Splunk Enterprise Cluster Administration This 3 day course is for an experienced Splunk Enterprise administrator who is new to Splunk Clusters. The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment. It covers installation, configuration, management and monitoring of Splunk clusters. Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk Enterprise Data Administration Training delivered by INGENIQ
Splunk Enterprise Data Administration Training delivered by INGENIQ Splunk Enterprise Data Administration The Splunk Enterprise Data Administration course (Version 9) is designed for system administrators who are responsible for getting data into Splunk Indexers. The Splunk Enterprise Data Administration course provides the fundamental knowledge of Splunk forwarders and methods to get remote data into Splunk indexers. It covers installation, configuration, management, monitoring, troubleshooting of Splunk forwarders and Splunk Deployment Server components. Splunk Credit Value : 225 Duration : 18 hours over 3 days Time : 9:00 am - 4:00 pm AEST *Course discounts apply for Splunk Partners. Please use the currency convertor above to check for course pricing in your local currency. Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! The instructor was very patient and worked with everyone who had issues and sorted them out. Thanks for that. Participant, Troubleshooting Splunk Splunk Enterprise Data Administration - Course Topics Understand sourcetypes Manage and deploy forwarders Configure data inputs Fire monitors Network inputs (TCP/UDP) Scripted inputs HTTP inputs (via the HTTP Event Collector) Customize the input phase parsing process Define transformations to modify data before indexing Define search time knowledge object configurations Course Prerequisites To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge: Intro to Splunk Using Fields Introduction to Knowledge Objects Creating Knowledge Objects Creating Field Extractions Enriching Data with Lookups Data Models Splunk Enterprise System TAdministration Splunk Enterprise Data Administration - Audience Anyone within a technical role who is involved in the management of Splunk within their organisation or are looking to become Splunk certified. Previous attendees have included IT Administrators, DevOps, Security Analysts and Solution Architects. Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Related Certifications Splunk Enterprise Certified Admin Splunk Enterprise Certified Architect Splunk Certified Enterprise Security Admin Splunk IT Service Intelligence Certified Admin After completing Splunk Enterprise Data Administration course you will be able to Install and Configure forwarders Get data into a production environment Maintain and manage forwarders Correctly create and maintain inputs: Files Directories Network Scripted Agentless Understand and work with the data input phases Inputs Parsing Indexing Splunk Enterprise Data Administration - Course Objectives Module 1 - Getting Data Into Splunk Provide an overview of Splunk Describe the Splunk distributed model Describe data input types and metadata settings Configure initial input testing with Splunk Web Testing indexes with Input Staging Module 2 - Configuration Files and Apps Identify Splunk configuration files and directories Describe index-time and search-time precedence Validate and update configuration files Explore Splunk apps and app installation Module 3 - Configuring Forwarders Configure Universal Forwarders Configure Heavy Forwarders Module 4 - Customizing Forwarders Configure intermediate forwarders Identify additional forwarder options Module 5 - Managing Forwarders Describe Splunk Deployment Server (DS) Manage forwarders using deployment apps Configure deployment clients and client groups Monitor forwarder management activities Module 6 - Monitor Inputs Create file and directory monitor inputs Use optional settings for monitor inputs Deploy a remote monitor input Module 7 - Network Inputs Create network (TCP and UDP) inputs Describe optional settings for network inputs Module 8 - Scripted Inputs Create a basic scripted input Module 9 - Agentless Inputs Configure Splunk HTTP Event Collector (HEC) agentless input Describe Splunk App for Stream Module 10 - Operating System Inputs Identify Linux-specific inputs Identify Windows-specific inputs Module 11 - Fine-tuning Inputs Understand the default processing that occurs during input phase Configure input phase options, such as source type fine-tuning and character set encoding Module 12 - Parsing Phase and Data Preview Understand the default processing that occurs during parsing Optimize and configure event line breaking Explain how timestamps and time zones are extracted or assigned to events Use Data Preview to validate event creation during parsing phase Module 13 - Manipulating Input Data Explore Splunk transformation methods Create rulesets with Ingest Actions Mask data with Ingest Actions rules Mask data with SEDCMD and TRANSFORMS Module 14 - Routing Input Data Filter data with Ingest Action rules Route data with Ingest Action rules Route data with Transforms Override sourcetype or host based upon event values Module 15 - Supporting Knowledge Objects Define default and custom search time field extractions Identify the pros and cons of indexed time field extractions Configure indexed field extractions Describe default search time extractions Manage orphaned knowledge objects Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Splunk Enterprise Data Administration - Upcoming Courses Splunk Enterprise Data Administration V9: Starts August 19 to 21, 2026 Price USD 2,250.00 Splunk Enterprise Data Administration V9: Starts July 22 to 24, 2026 Course Closed
- Implementing Splunk SmartStore Training delivered by INGENIQ
Implementing Splunk SmartStore Training delivered by INGENIQ Implementing Splunk SmartStore The Implementing Splunk SmartStore course is designed for the experienced Splunk system administrators. This hands-on class is designed to provide the essential knowledge for deploying and managing Splunk SmartStore. It covers SmartStore deployment options, cache manager configurations, monitoring, and troubleshooting of SmartStore implementation. Units : 1 Duration : 4.5 hours over 1 day Time : 9:00 am – 1:30 pm AEST (GMT +11) *Course discounts apply for Splunk Partners. Please use the currency convertor above to check for course pricing in your local currency. Extremely proficient at controlling the pace of training. Great explanation of answers & not just reading the content. Very knowledgeable about all content. Looking forward to completing the rest of the of the class. Highly recommended. Participant, Splunk Enterprise Data Administration Implementing Splunk SmartStore - Course Topics Introduction to SmartStore Standalone SmartStore Implementation SmartStore in Indexer Cluster Monitoring and managing SmartStore Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites Fundamentals 1 (Required) Splunk System Administration (Required) Splunk Data Administration (Required) Troubleshooting Splunk Enterprise (Recommended) Working knowledge of: (Recommended) o Linux OS commands o Editing files with vi or nano o Splunk index life-cycle and bucket transitions o Splunk Indexer cluster concept Related Certifications None Implementing Splunk SmartStore - Audience Splunk Admins and Architects managing large Splunk environments on premise or in private cloud who are interested in learning to cut cost and improve performance on storage. After completing Implementing Splunk SmartStore course you will be able to Learn Benefits of SmartStore other than cost savings How to implement and troubleshoot Smartstore How to Migrate data from onboard storage to Smartstore How to Monitor and manage Storage in Indexer clusters using SmartStore Module 1 – Introduction to SmartStore Benefits of SmartStore SmartStore requirements and restrictions Indexing in SmartStore Searching in SmartStore Module 2 – Standalone SmartStore Implementation Enabling SmartStore indexes Bootstrapping SmartStore indexes Validating the implementation Implementing Splunk SmartStore - Course Objectives Module 3– SmartStore in Indexer Cluster Implementation differences between deployments SmartStore in an indexer cluster SmartStore migration in indexer clusters Module 4 – Monitoring and managing SmartStore Monitoring SmartStore activities Cache manager settings & Optimizing eviction policies Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses start at AET 2:00pm and finish at AET 6:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas; UTC+9 including Japan, Korea UTC+8 including Australia (West Coast), Singapore, Hong Kong, China, Philippines, Brunei, Thailand UTC +5/+6 including India and Sri Lanka Implementing Splunk SmartStore - Upcoming Courses We don’t have any products to show here right now.
- Enterprise Security Administrators | INGENIQ
Splunk Education, Training and Professional Services Provider Splunk Enterprise Administrators Learn to install, configure, manage, and use the Splunk App for Enterprise Security. This path is intended for Splunk Administrators that manage Splunk Enterprise Security deployments. Splunk Enterprise Administrators Track Courses Splunk Fundamentals 1 Splunk Fundamentals 2 Creating Dashboards with Splunk Splunk Fundamentals 3 Advanced Dashboards and Visualisations Splunk Enterprise System Administration Splunk Enterprise Data Administration Architecting Splunk Enterprise Deployments Administering Splunk Enterprise Security One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk IT Service Intelligence Certified Administrator Splunk Certification | INGENIQ
Splunk IT Service Intelligence Certified Administrator Splunk Certification | INGENIQ Splunk IT Service Intelligence Certified Administrator As part of Splunk Certification, a Splunk IT Service Intelligence Certified Admin installs and configures Splunk’s app for IT Service Intelligence (ITSI), including ITSI architecture, deployment planning, service design and implementation, notable events and developing glass tables and deep dives. This Splunk Certification demonstrates an individual’s ability to deploy, manage and utilise Splunk ITSI to monitor mission-critical services. Please note: There are two approved coursework paths for this Splunk Certification track. Candidates may complete either Splunk Enterprise System Administration and Splunk Enterprise Data Administration or Splunk Cloud Administration as part of this certification track. Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Learning Path Free Training Paid Training Paid Cert Exam Splunk Enterprise System Administration Splunk Enterprise Data Administration Splunk Cloud Administration Implementing Splunk IT Service Intelligence Cert Exam - Splunk IT Service Intelligence Certified Admin Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk Core Certified Consultant Splunk Certification | INGENIQ
Splunk Core Certified Consultant Splunk Certification | INGENIQ Splunk Core Certified Consultant As part of Splunk Certification, a Splunk Core Certified Consultant has a thorough understanding of Splunk Deployment Methodology and implementation in large Splunk installations and has expert-level knowledge of multi-tier Splunk architectures, clustering, and scalability topics. This certification demonstrates a Consultant’s ability to properly size, install, and implement Splunk environments and to advise others on how to utilize the product and maximize its value for their needs. You can download the Splunk Certification Candidate Handbook to learn more about the changes. Learning Path Paid Cert Exam Paid Training Labs Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! Cert Exam - Splunk Core Certified Power User Cert Exam - Splunk Enterprise Certified Admin Splunk Enterprise Practical Lab Cert Exam - Splunk Enterprise Certified Architect Core Consultant Labs Services Core Implementation Cert Exam - Splunk Core Certified Consultant Splunk Certifications Exam When you’re ready to take a Splunk Certification exam, please view the Exam-Registration-Tutorial for registration assistance. As a reminder, each exam attempt costs US$125. Bulk registration vouchers can be purchased at a discounted price of five registrations for US$500. How to register for your exam There are three ways to purchase a PearsonVUE registration voucher: 1) Directly from PearsonVUE This is the most streamlined approach. Follow the steps for account creation and exam registration provided at www.pearsonvue.com/splunk Payment will be collected at the time of registration. You can also visit the Pearson VUE voucher store for direct purchase. 2) From Splunk (as an individual) Log into your existing account at Splunk.com/Education to purchase a registration code. Payment can be made via credit card or existing Splunk Education credits. Splunk will email you a unique registration code, which can be used for registration at www.pearsonvue.com/splunk . 3) From Splunk (as an account) Your Splunk Sales Rep can add certification exams to any deal. Once the number of vouchers has been requested, Splunk will email your unique registration codes, which can be used for registration at www.pearsonvue.com/splunk All scheduled exams are subject to a minimum 24-hour cancellation and/or rescheduling policy. Failure to cancel or reschedule an exam within this timeframe results in forfeiture of registration fee. One of the best trainers I've had - keeps content relevant & explains the tasks in easily understood language. Extremely knowledgeable in all fields relating to the content. Well paced & accommodated to everyone's questions & progress. Participant, Splunk Enterprise Data Administration
- Splunk Cloud Administration Training delivered by INGENIQ
Splunk Cloud Administration Training delivered by INGENIQ Splunk Cloud Administration This 18-hour (4 day) hands-on Splunk Cloud Administration course prepares administrators to manage users and get data in Splunk Cloud. Modules include data inputs and forwarder configuration, data management, user accounts, and basic monitoring and problem isolation. Splunk Cloud Administration course provides administrators with the skills, knowledge and best practices for data management and system configuration for data collection and ingestion in a Splunk Cloud environment to maintain a productive Splunk SaaS deployment. Splunk Credit Value : 200 Duration : 18 hours over 4 days Time : 9:00 am - 1:30 pm AEST *Course discounts apply for Splunk Partners. Please use the currency convertor above to check for course pricing in your local currency. Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit The instructor was very responsive to questions and queries both private and Communal.. Final module collaborative lab walkthrough on screen was particularly helpful. Participant, Splunk Fundamentals 2 Splunk Cloud Administration - Course Topics Splunk Cloud overview User Authentication and Authorization Index Management and Data Retention Splunk configuration files Cloud Ingestion – Using Splunk forwarders Forwarder management Data inputs in detail Cloud Ingestion – Use API, Scripted, HEC and Applications Event Parsing with data preview Manipulating raw data Installing and managing applications Problem isolation and working with Splunk Cloud support Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge: Intro to Splunk Using Fields Introduction to Knowledge Objects Creating Knowledge Objects Creating Field Extractions Additional courses and/or knowledge in these areas are also highly recommended: Enriching Data with Lookups Data Models Splunk Cloud Administration - Audience Splunk Partners having a Professional Services Practice Splunk Cloud Customers Related Certifications Splunk Cloud Certified Admin After completing Splunk Cloud Administration course you will be able to Deploy and manage on premise components for data collection Create and configure indexes in Splunk Cloud including archiving and restoration. Manage data and input configuration using OnPrem and Cloud IDM Manage Apps and Configs in Splunk Cloud Splunk Cloud Administration - Course Objectives Module 1 -Splunk Cloud Overview Describe Cloud topology Describe tasks managed by the Splunk cloud administrator List the primary differences between Splunk Cloud and Splunk Enterprise List differences between Self-Service Cloud and Managed Cloud Module 2 - Index Management Define a Splunk Index Create indexes in cloud Delete data from an index Monitor indexing activities Module 3 - User Authentication and Authorization Administer Splunk user roles Integrate Splunk with LDAP, Active Directory, or SAML Module 4 -Splunk Configuration Files Review Splunk configuration files and directories Review configuration file precedence Review index and search time processes Module 5 – Cloud Ingestion – Using Splunk Forwarders Review cloud ingestion strategies Understand the role of forwarders in GDI Configure forwarding to Splunk Cloud Monitoring forwarder connectivity Explore optional forwarder settings Module 6 – Forwarder Management Describe Splunk Deployment Server Explain the use of forwarder management Configure forwarders to be deployment clients Managing forwarders using deployment apps Module 7 – Monitor Inputs Describe the Splunk process for inputting data Create file and directory monitor inputs Use optional settings for monitor inputs Module 8 – Cloud Ingestion – Using API, Scripted and HEC Inputs Understand how data is ingested using API Know how to deploy scripted inputs Describe how to use HEC for ingestion Module 9 – Cloud Ingestion – Application Based Inputs Understand how inputs are managed using in apps or add-ons Describe how customers may use Splunk Stream app Deploy Cloud inputs for use on an IDM Module 10 – Fine-tuning Inputs Describe the default processing that occurs during the input phase Configure input phase options, such as source type fine-tuning and character set encoding Module 11 – Parsing Phase and Data Preview Describe the default processing that occurs during parsing Optimize and configure event line breaking Explain how timestamps and time zones are extracted or assigned to events Use Data Preview to validate event creation during the parsing phase Module 12 – Manipulating Raw Data Explain how data transformations are defined and invoked Use transformations with props.conf and transforms.conf to modify raw data Use SECCMD to modify raw data Module 13 – Installing and Managing Apps Understand how apps and add-ons are vetted and installed in Cloud Create apps to managing and distribute configurations Module 14 – Splunk Cloud Support and Troubleshooting Troubleshooting Splunk Deployments Collecting data and use diagnostics or monitoring to investigate Overview of how to collect the relevant data for support to troubleshoot Splunk Course Schedules and Timezones Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Splunk Cloud Administration - Upcoming Courses Splunk Cloud Administration : Starts September 1 to 4, 2026, 9:00am AEST Price USD 2,000.00 Splunk Cloud Administration : Starts July 28 to 31, 2026, 9:00am AEST Course Closed
- Introduction to Dashboards - Splunk Education Single Subject Course Training
Introduction to Dashboards - Splunk Education Single Subject Course Training. Introduction to Dashboards The Splunk Education single-subject course module, Introduction to Dashboards is designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. This course focuses on dashboard creation, including prototyping, the dashboard definition, layouts types, adding visualizations, and dynamic coloring. Splunk Credit Value : 50 Duration : 3 hours Time : 9:00 am - 12:00 pm AEST Please use the currency convertor above to check for course pricing in your local currency. Enquiry Form Let us know what you're after Courses for me Certifications for me Courses for my team Dedicated courses for my teams Training Tracks for my Company Dedicated courses for my Company Training Packs Using Splunk Training Credits Submit Thanks for submitting! The instructor was very responsive to questions and queries both private and Communal.. Final module collaborative lab walkthrough on screen was particularly helpful. Participant, Splunk Fundamentals 2 Introduction to Dashboards - Course Topics Dashboard Framework Prototyping Visualization Types Modifying the Source Code Dynamic Coloring Class Format Instructor-led lecture with labs. Delivered via virtual classroom or at your site Course Prerequisites To be successful, students must have a solid understanding of these courses: Intro to Splunk Using Fields Search Optimization Introduction to Dashboards - Audience Knowledge Manager learning path Introduction to Dashboards- Course Objectives Topic 1 – Dashboard Framework Describe the dashboard definition Compare classic and dashboard studio dashboards Use dashboard best practices Manage views Use dashboard best practices Topic 2 – Create a Prototype Describe dashboard workflows Compare layout types Identify layout fields Add visualizations Topic 3 - Use Dynamic Coloring Describe dynamic coloring Contrast visualization types Set global time range parameters Apply dynamic coloring Splunk Course Schedules and Timezones Splunk Course are delivered live and in English and provide access to customers spanning multiple timezones. Dates and times displayed for each course are relative to Australian Eastern Time (AET). AM Marked Splunk Courses AM marked courses start at AET 9:00am and finish at AET 1:30pm and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) PM Marked Splunk Courses PM marked courses usually starts at AEDT 12:00pm or AEST 11:00 am and are optimal for customers in the following countries and areas; UTC+10 including Australia (East Coast) UCT+11/+12 including New Zealand and the Pacific Islands UTC-8 including USA (West Coast), Canada (West Coast) UTC-7 including USA (Mid West) Introduction to Dashboards - Upcoming Schedule We don’t have any products to show here right now.
