UPDATED FOR SPLUNK 8.x
LEARN SPLUNK, PASS THE SPLUNK CERTIFICATION EXAMS, BECOME THE IT HERO
One of my students, who gave me permission to post this, says:
*****
“Rated you 5 stars! Your course was amazing. I bought your course, got started on Saturday, went through all the videos and exercises. Then re-watched it again on Sunday at 1.5 speed…and got a job Monday working with Splunk! Every technical question they threw at me I was able to answer including example SPL. This was an amazing life changing decision to take this course.” – Neil
*****
-
Course updated for Splunk 8.x! As Splunk updates their software, I’ll update this course content, and you don’t have to purchase anything else!
-
Lifetime access
-
Lots of downloadable content
-
All slides available for download
-
Custom, helpful documents made just for you!
-
The best course for learning Splunk, the leader in real-time monitoring, operational intelligence, log management, and SIEM (security information and event management). Your instructor is Adam Frisbee, a university instructor, a Splunk Certified Administrator and a Splunk geek.
Do you want to be an IT Hero? This course is for you!
In this course we will go through Splunk architecture, setting up your own Splunk instance, searching and reporting with Splunk, creating cool visualizations in Splunk, and much more!
Don’t buy poor quality courses! This course is high quality, with hours and hours of video content, downloadable slide decks for every lecture, practice problems and data sets, and quizzes that really test your knowledge after each section.
*Some of the demos might be using a slightly older version of Splunk. I am working on updating these.
Introduction
I'm glad you have decided to enroll in this, the most popular Splunk course ever created. In the resources for this lecture, I have included all of the course resources: slides, datasets, and helpful documents, in one convenient .zip file. Download here!
Resources for when you get stuck.
A few questions to get the ball rolling. Once you pass with 100%, you can feel confident in moving on to Section 2.
Planning Your Splunk Deployment
Learn about some of the different deployment models for Splunk.
Maps to 2.1 Identify license types
Maps to 2.2 Understand license violations
Apps are one of the things that set Splunk apart from other log management tools.
Installing Splunk
After you pass this quiz (100%), you will be ready to move on to section 3 "Getting Data In."
For the first homework assignment, please see the available .pdf.
Getting data In
Learn how you can get data into Splunk.
Forwarders are the most popular way to get data into Splunk. Universal forwarders are the most popular (and easiest to deploy) type of forwarder.
For the second homework assignment, please see the available .pdf.
Once you've passed this quiz with 100%, you're ready to move on to Section 4: Searching and Reporting. You're half-way done with the course!
Searching and Reporting
The Search app is the starting place for many Splunk functions.
Understand how Splunk interprets your search commands.
The basics of SPL. Key value pairs, comparisons, phrases, wildcards, booleans
Time is arguably the most valuable property of a Splunk search.
Understand how Splunk detects fields, and how you can define your own fields.
Add functions to your search: stats, rare, top.
Test your knowledge with SPL!
Visualizing Your Data
One of the most powerful features of Splunk is the data model.
Learn to use Splunk's visualization builder to build your own dashboards and reports.
Build visualizations using SPL.
Learn how to create and schedule reports and alerts.
For the fourth homework assignment, we're going to import a data set and do some searches against it using SPL, then create a cool dashboard.
- You'll need to download and import the homeworkdataset.csv file.
- The assignment is described in the homework 3.pdf file.
Advanced Splunk Concepts
Understand how Splunk handles users, roles, and authentication--both internal and external.
Configuration files are the "atoms" of Splunk--the stuff Splunk is made out of.
Learn about the power of knowledge objects: tags, fields, lookups, eventtypes
This is the end of this course, but it is only the beginning of your Splunk journey!
Watch this video to learn about Splunk's cloud offering and how you can get a free trial!
Welcome to this comprehensive final exam. As you are answering these questions, reflect back on how much you now know about Splunk.