Splunk is an enterprise platform utilized by IT, security, and data professionals to search, monitor, and analyze machine-generated data. Whether you are new or want to gain deeper insight, Splunk offers an extensive array of online training. These online courses are categorized into various product categories depending on use cases such as data analysis, security operations, system monitoring, and administration.
Explore each product category and explain the types of Splunk courses you can take online.
Splunk Core Platform Courses
The Core Platform serves as the foundation for all Splunk products. The Core Platform courses are perfect for anyone new to Splunk and looking to learn how to search, view, and analyze data using Splunk.
What will you learn:
- How to navigate the Splunk interface
- Basic and advanced search techniques
- Creating reports, alerts, and dashboards
- Working with fields, lookups, and knowledge objects
Best for:
- Beginners
- Data analysts
- IT professionals, starting with Splunk
Course Name |
Description |
Duration |
USPs |
Splunk Fundamentals 1 |
Introduction to Splunk's interface, basic searching, and creating alerts and reports. |
Self-paced |
- Free eLearning
- Foundational course for beginners.
|
Splunk Fundamentals 2 |
Advanced searching techniques, creating knowledge objects, and data models. |
Self-paced |
- Prepares for Splunk Core Certified Power User exam.
|
Splunk Core Certified User |
Validates ability to search, use fields and lookups, and create basic reports and dashboards. |
Exam-based |
- Entry-level certification
- Demonstrates core Splunk skills.
|
Splunk Core Certified Power User |
Demonstrates proficiency in advanced searching and reporting commands and knowledge of object creation. |
Exam-based |
- Intermediate certification
- Builds on Core Certified User skills.
|
Creating Field Extractions |
Master the creation of field extractions to structure data. |
Self-paced |
- Key for customizing data inputs
|
Enriching Data with Lookups |
Use lookups to add context to your data. |
Self-paced |
|
Data Models |
Understand and build data models for Pivot and other tools. |
Self-paced |
- Foundation for advanced analytics
|
Search Under the Hood |
Dive deep into how Splunk processes searches. |
Self-paced |
- Advanced understanding of search mechanisms
|
Splunk Enterprise System Administration |
Learn administrative tasks, such as managing users and configuring inputs. |
Instructor-led |
- Essential for system administrators
|
Splunk Security Courses
Splunk is widely used in security operations centers (SOCs) for real-time threat detection and response. The Security category focuses on tools like Splunk Enterprise Security and Splunk SOAR.
What will you learn:
- How to use Splunk to investigate and respond to security incidents
- Creating automated workflows using SOAR playbooks
- Building custom security use cases
Best for:
- Security analysts
- SOC engineers
- Cybersecurity professionals
Course Name |
Description |
Duration |
USPs |
Investigating Incidents with Splunk SOAR |
Teaches how to use SOAR to respond to security incidents and investigate vulnerabilities. |
3 hours |
- Hands-on experience with SOAR.
- Suitable for security practitioners.
|
Developing SOAR Playbooks |
Focuses on creating and managing playbooks for security automation and orchestration. |
Varies |
- Essential for automation engineers
- Enhances incident response skills.
|
Splunk Security Use Case Development |
Guides on developing security use cases using Enterprise Security Content Updates and Security Essentials. |
Varies |
|
Administering Splunk Enterprise Security |
Manage and configure Splunk Enterprise Security. |
Instructor-led |
- Comprehensive ES administration
|
Security Use Case Implementation |
Implement specific security use cases in Splunk. |
Instructor-led |
- Practical application of security scenarios
|
Threat Hunting with Splunk |
Learn techniques for proactive threat hunting. |
Instructor-led |
- Enhances threat detection capabilities
|
Splunk Phantom Administration |
Administer and manage Splunk Phantom. |
Instructor-led |
- Focus on the Phantom platform
|
Splunk Phantom Playbook Development |
Develop playbooks specifically for Splunk Phantom. |
Instructor-led |
- Specialized in Phantom automation
|
Splunk Observability Courses
Splunk Observability courses are designed for professionals responsible for monitoring and enhancing application performance, infrastructure, and services. These tools are essential in DevOps, Site Reliability Engineering, and cloud environments.
What will you learn:
- Application and infrastructure monitoring using dashboards and metrics
- Proactive performance testing using synthetic monitoring
- Real-time insights with Splunk IT Service Intelligence (ITSI)
Best for:
Course Name |
Description |
Duration |
USPs |
Introduction to Splunk Application Performance Monitoring (APM) |
Overview of Splunk APM's features, navigation, and basic troubleshooting. |
15 minutes |
- Quick introduction to Splunk Application Performance Monitoring
- Suitable for developers and SREs.
|
Using Splunk Synthetic Monitoring |
Learn to create and manage synthetic tests to monitor web performance. |
Varies |
- Enhances proactive troubleshooting.
- Beneficial for performance engineers.
|
Using Splunk IT Service Intelligence (ITSI) |
Covers features like Service Analyzer, Notable Events Review, and KPI Alerts. |
6 hours |
- Comprehensive ITSI training
- Ideal for IT analysts and administrators.
|
Infrastructure Monitoring with Splunk |
Monitor infrastructure using Splunk tools. |
Instructor-led |
- Focus on infrastructure health
|
Application Performance Monitoring with Splunk |
Track and optimize application performance. |
Instructor-led |
- Enhances application reliability
|
Real User Monitoring with Splunk |
Understand user interactions and experiences. |
Instructor-led |
- Improves user experience insights
|
Synthetic Monitoring with Splunk |
Simulate user interactions to monitor applications. |
Instructor-led |
- Proactive performance testing
|
Splunk On-Call Administration |
Manage on-call schedules and incident responses. |
Instructor-led |
- Streamlines incident management
|
Splunk Administration Courses
If you are responsible for installing, setting up, or maintaining Splunk, then the Splunk Administration Courses are for you. These courses will help you understand how to deploy Splunk in enterprise settings, handle data inputs, and fine-tune performance.
What will you learn:
- Administering user roles and permissions
- Managing data inputs and forwarders
- Configuring indexers and managing storage
- Monitoring system health and troubleshooting
Best for:
- System administrators
- IT infrastructure teams
- DevOps and cloud engineers
Course Name |
Description |
Duration |
USPs |
Splunk Enterprise System Administration |
Teaches how to manage users, configure data inputs, and maintain Splunk Enterprise. |
Varies |
- Essential for system administrators
- Covers core administrative tasks.
|
Splunk Enterprise Data Administration |
Focuses on configuring and managing data inputs and forwarders. |
Varies |
- Crucial for data administrators
- Ensures efficient data ingestion.
|
Splunk Cloud Administration |
Provides knowledge on administering Splunk Cloud Platform. |
Varies |
|