| Level |
Topic |
Sub-Topics |
| 1 | Splunk Overview | What is Splunk, Splunk Use Cases, Machine Data, Splunk Architecture, Real-time vs Historical Data |
| 2 | Splunk Installation | System Requirements, Splunk Enterprise Install, Forwarder Install, Windows Install, Linux Install |
| 3 | Splunk Components | Indexer, Search Head, Forwarder, Deployment Server, License Master |
| 4 | Splunk Data Inputs | Files & Directories, TCP/UDP Inputs, Scripted Inputs, Windows Event Logs, Syslog |
| 5 | Splunk Indexing Process | Parsing Phase, Indexing Phase, Buckets, Hot/Warm/Cold Buckets, Metadata |
| 6 | Splunk Web Interface | Search Bar, Apps Menu, Dashboards, Settings, Monitoring Console |
| 7 | SPL Basics | Search Command, Keywords, Time Range Picker, Pipes, Fields |
| 8 | SPL Searching & Filtering | AND/OR/NOT, Wildcards, Field Searches, Time Modifiers, Subsearch |
| 9 | Fields & Field Extraction | Default Fields, Field Discovery, Regex Extraction, Delimiters, Field Aliases |
| 10 | Transforming Commands | stats, chart, timechart, top, rare |
| 11 | Reporting in Splunk | Report Creation, Scheduling Reports, Export Formats, Sharing Reports, Report Acceleration |
| 12 | Splunk Dashboards | Dashboard Panels, Visualization Types, XML Dashboards, Tokens, Inputs |
| 13 | Lookups | Lookup Tables, CSV Lookups, Automatic Lookups, Lookup Commands, Geo Lookups |
| 14 | Knowledge Objects | Fields, Tags, Event Types, Macros, Workflow Actions |
| 15 | Splunk Apps & Add-ons | Splunkbase, App Installation, Add-on Configuration, CIM Compliance, App Permissions |
| 16 | Common Information Model (CIM) | CIM Overview, Data Models, Normalization, Tags & Fields, CIM Validation |
| 17 | Data Models | Data Model Structure, Pivot, Acceleration, Constraints, Datasets |
| 18 | Alerts in Splunk | Alert Types, Alert Conditions, Throttling, Actions, Email & Webhook Alerts |
| 19 | User Management | Users & Roles, Capabilities, Authentication, Authorization, Role Mapping |
| 20 | Splunk Security Basics | RBAC, Secure Ports, TLS/SSL, Audit Logs, Password Policies |
| 21 | Forwarder Management | Universal Forwarder, Heavy Forwarder, Deployment Server, Server Classes, Outputs.conf |
| 22 | Configuration Files | inputs.conf, outputs.conf, props.conf, transforms.conf, limits.conf |
| 23 | Performance Tuning | Search Optimization, Index Sizing, Bucket Management, Resource Monitoring, Acceleration |
| 24 | Monitoring Console | Indexer Health, Search Head Health, Forwarder Status, Resource Usage, Alerts |
| 25 | Splunk REST API | REST Basics, Authentication, Search API, Admin API, Use Cases |
| 26 | Splunk Backup & Restore | Index Backup, Config Backup, Cold to Frozen, Restore Process, Best Practices |
| 27 | Splunk Scaling | Distributed Search, Indexer Clustering, Search Head Clustering, Load Balancing, High Availability |
| 28 | Troubleshooting Splunk | Search Issues, Indexing Issues, Forwarder Issues, Log Files, Common Errors |
| 29 | Splunk Use Cases | Log Monitoring, Security Analytics, IT Operations, Business Analytics, Compliance |
| 30 | Splunk Interview & Certification Prep | Common Interview Questions, SPL Scenarios, Admin Concepts, Architect Concepts, Certification Path |