Splunk Enterprise
Admin Essentials
(Day-1 to 30)
Admin Essentials
(Day-1 to 30)
About the Course
Course Topics
Create a Splunk.com account.
Download Splunk Enterprise's latest version (or) specific version.
Download Splunk Universal Forwarder’s latest version (or) specific version.
Request Splunk Developer License.
How to create a Linux EC2 instance in AWS.
Tools to be installed on your laptop. - Optional
Install Splunk Enterprise on 2 Linux EC2 instances.
Install Splunk Universal Forwarder on the Linux EC2 instance.
Connect UF with Indexer.
Connect Search Head with Indexer.
Create indexes in Indexer. (Web/Conf/CLI).
Download sample data from GitHub.
Upload data on the Indexer UI & search the data from the Search Head.
Monitor files from UF & search the data from Seach Head.
What is the difference between Standalone, distributed, and Clustered deployment?
Why do we need 3 different components? Why can’t we manage it with a single component with a huge hardware capacity to handle the load?
What data can I Index?
How to get data into your Splunk deployment - High Level?
How does Splunk Enterprise handle your data? - Standalone
How does Splunk Enterprise store your data? - Standalone
Can Forwarders store the data? Why?
Can Search Heads store the data? Why?
How to design & size the indexes? - Standalone
How to estimate storage requirements for Splunk servers? - Standalone
How to estimate/find/calculate License usage?- Standalone
What are all the types of Licenses available & How to request them?
The difference between a Universal Forwarder and a Heavy Forwarder
How to select a Forwarder?
What are all the Processing Components & why do we need them?
What are all the Management Components & why do we need them?
Which component will you set up first & why?
Setup License Master from UI
Setup Cluster Master from UI
Setup Indexer Cluster from UI
Setup Deployer
Setup Search Head Cluster
Connect Search Head Cluster with Indexer Cluster
Setup Deployment Server and manage Multiple Forwarders
Setup Forwarders
Setup Monitoring Console
How to update Splunk’s default configurations
How do you do a basic health check of the Splunk infrastructure?
Registration Form