Splunk Foundation builds attendees’ foundational understanding of Splunk through lecture and interactive hands-on exercises, taking students from raw log data to production-ready searches, reports, and alerts over two days.
Day one opens with a Splunk overview covering the interface, data model, and how indexes and events organize incoming data. Search fundamentals follow, teaching basic and field-based searching with Splunk’s Boolean and comparison operators. Students then build search pipelines with the Search Processing Language (SPL), comparing streaming and non-streaming commands and applying filtering and field modification. The day closes with transforms and aggregation, using transforming and statistical commands and subsearches to summarize results.
Day two starts with lookups, data models, and pivot, enriching events with lookups, working with datasets and the Common Information Model (CIM), and building pivot reports. Attendees then create and interact with reports, accelerated and scheduled reports, and dashboards that surface trends at a glance without another manual search. An alert management module covers alert types, triggers, throttling, and alert actions and permissions, so notifications reach the right team without flooding it. The course closes with developing for Splunk: REST API operations, embedding Splunk knowledge objects in web services, and custom field extractions. Scenario-based examples and hands-on challenges enable attendees to create robust searches, reports, and charts.
Who Should Attend
IT managers, IT Team Members, Developers, Analysts, SREs, DevOps staff and Testers
What Attendees Will Learn
Upon completing Splunk Foundation, attendees will be able to:
- Navigate the Splunk interface and understand its data model, indexes, and events
- Write basic and field-based searches using Splunk’s search operators
- Build search pipelines using the Search Processing Language (SPL)
- Transform and aggregate search results using statistical commands and subsearches
- Enhance data with lookups and build pivot reports using data models
- Create and manage reports, dashboards, and scheduled reports
- Configure alerts, including triggers, throttling, and alert actions
- Use the Splunk REST API to develop against Splunk programmatically
Prerequisites
No prior Splunk experience is required. General familiarity with IT operations, log data, or systems monitoring is helpful.