| Introduction |
What is Splunk, Features, Benefits |
✅ |
✅ |
✅ |
✅ |
| Installation & Setup |
On-prem, Cloud, System requirements |
✅ |
✅ |
✅ |
✅ |
| UI Navigation |
Splunk Web, Dashboards, Search UI |
✅ |
✅ |
✅ |
✅ |
| Authentication & Authorization |
Users, Roles, Permissions |
✅ |
✅ |
✅ |
✅ |
| Basic Searches |
Search bar, Keywords, Time range |
✅ |
✅ |
✅ |
✅ |
| Alerts |
Real-time vs Scheduled alerts, Trigger conditions |
✅ |
✅ |
✅ |
✅ |
| Forwarders |
Universal, Heavy, Deployment server |
✅ |
✅ |
✅ |
✅ |
| Indexing Basics |
Index creation, Event ingestion |
✅ |
✅ |
✅ |
✅ |
| Reports |
Creating basic reports, Exporting data |
✅ |
✅ |
✅ |
✅ |
| Community & Resources |
Documentation, Forums, Splunkbase |
✅ |
✅ |
✅ |
✅ |
| Data Ingestion |
Forwarders, Inputs, Data sources |
|
✅ |
✅ |
✅ |
| Indexing |
Index types, Index configuration, Retention policies |
|
✅ |
✅ |
✅ |
| Search Processing Language (SPL) |
Commands, Functions, Joins |
|
✅ |
✅ |
✅ |
| Dashboards & Visualizations |
Panels, Charts, Dynamic dashboards |
|
✅ |
✅ |
✅ |
| Alerts & Reports |
Scheduled alerts, Real-time alerts, Reporting best practices |
|
✅ |
✅ |
✅ |
| Knowledge Objects |
Saved searches, Event types, Tags, Fields |
|
✅ |
✅ |
✅ |
| Clustering |
Indexer clustering, Search head clustering, Multi-site setup |
|
|
✅ |
✅ |
| Advanced SPL |
Subsearches, Macros, Lookups, Optimizations |
|
|
✅ |
✅ |
| Performance Tuning |
Query optimization, Indexing performance, Resource management |
|
|
✅ |
✅ |
| Enterprise Deployment |
High availability, Disaster recovery, Multi-site replication |
|
|
✅ |
✅ |