Introduction |
What is Splunk, Features, Benefits |
✅ |
✅ |
✅ |
✅ |
Installation & Setup |
On-prem, Cloud, System requirements |
✅ |
✅ |
✅ |
✅ |
UI Navigation |
Splunk Web, Dashboards, Search UI |
✅ |
✅ |
✅ |
✅ |
Authentication & Authorization |
Users, Roles, Permissions |
✅ |
✅ |
✅ |
✅ |
Basic Searches |
Search bar, Keywords, Time range |
✅ |
✅ |
✅ |
✅ |
Alerts |
Real-time vs Scheduled alerts, Trigger conditions |
✅ |
✅ |
✅ |
✅ |
Forwarders |
Universal, Heavy, Deployment server |
✅ |
✅ |
✅ |
✅ |
Indexing Basics |
Index creation, Event ingestion |
✅ |
✅ |
✅ |
✅ |
Reports |
Creating basic reports, Exporting data |
✅ |
✅ |
✅ |
✅ |
Community & Resources |
Documentation, Forums, Splunkbase |
✅ |
✅ |
✅ |
✅ |
Data Ingestion |
Forwarders, Inputs, Data sources |
|
✅ |
✅ |
✅ |
Indexing |
Index types, Index configuration, Retention policies |
|
✅ |
✅ |
✅ |
Search Processing Language (SPL) |
Commands, Functions, Joins |
|
✅ |
✅ |
✅ |
Dashboards & Visualizations |
Panels, Charts, Dynamic dashboards |
|
✅ |
✅ |
✅ |
Alerts & Reports |
Scheduled alerts, Real-time alerts, Reporting best practices |
|
✅ |
✅ |
✅ |
Knowledge Objects |
Saved searches, Event types, Tags, Fields |
|
✅ |
✅ |
✅ |
Clustering |
Indexer clustering, Search head clustering, Multi-site setup |
|
|
✅ |
✅ |
Advanced SPL |
Subsearches, Macros, Lookups, Optimizations |
|
|
✅ |
✅ |
Performance Tuning |
Query optimization, Indexing performance, Resource management |
|
|
✅ |
✅ |
Enterprise Deployment |
High availability, Disaster recovery, Multi-site replication |
|
|
✅ |
✅ |