Splunk Foundation

}
2 Days

Available On-Site

Available Virtually

Contact Us for Open Enrollment
f

Customizable

Splunk Foundation builds attendees’ foundational understanding of Splunk through lecture and interactive hands-on exercises, taking students from raw log data to production-ready searches, reports, and alerts over two days.

Day one opens with a Splunk overview covering the interface, data model, and how indexes and events organize incoming data. Search fundamentals follow, teaching basic and field-based searching with Splunk’s Boolean and comparison operators. Students then build search pipelines with the Search Processing Language (SPL), comparing streaming and non-streaming commands and applying filtering and field modification. The day closes with transforms and aggregation, using transforming and statistical commands and subsearches to summarize results.

Day two starts with lookups, data models, and pivot, enriching events with lookups, working with datasets and the Common Information Model (CIM), and building pivot reports. Attendees then create and interact with reports, accelerated and scheduled reports, and dashboards that surface trends at a glance without another manual search. An alert management module covers alert types, triggers, throttling, and alert actions and permissions, so notifications reach the right team without flooding it. The course closes with developing for Splunk: REST API operations, embedding Splunk knowledge objects in web services, and custom field extractions. Scenario-based examples and hands-on challenges enable attendees to create robust searches, reports, and charts.

Who Should Attend

IT managers, IT Team Members, Developers, Analysts, SREs, DevOps staff and Testers

What Attendees Will Learn

Upon completing Splunk Foundation, attendees will be able to:

  • Navigate the Splunk interface and understand its data model, indexes, and events
  • Write basic and field-based searches using Splunk’s search operators
  • Build search pipelines using the Search Processing Language (SPL)
  • Transform and aggregate search results using statistical commands and subsearches
  • Enhance data with lookups and build pivot reports using data models
  • Create and manage reports, dashboards, and scheduled reports
  • Configure alerts, including triggers, throttling, and alert actions
  • Use the Splunk REST API to develop against Splunk programmatically

Prerequisites

No prior Splunk experience is required. General familiarity with IT operations, log data, or systems monitoring is helpful.

Delivery

Available for Instructor-Led (ILT) in-person/onsite training or Virtual Instructor-Led training (VILT) delivery.

Each attendee will require the ability to ssh into a cloud hosted virtual machine (provided with the course). In environments where SSH is not possible, local lab VMs or browser accessible lab systems can be provided. For web-based delivery, participants require an Internet-connected computer capable of teleconferencing.

Related Instructor-Led (ILT & VILT) Training Courses

If you are interested in other Cloud Native, AI, programming, or other courses, check out the full course list or search our entire catalog:

Secret Link