Splunk Engineering: Intermediate Level
Course Curriculum
Beyond Search Fundamentals
-
Review Basic Search Commands
-
Use Case correctly in Searches
-
Describe Splunk’s Search Process
Commands for Visualizations
-
Explore Data Structure Requirements
-
Explore Visualization Types
-
Create and Format Charts
-
Create and Format Timecharts
-
Explain when to use each type of Reporting Command
Advanced Visualizations
-
Create a Trendline
-
Create Maps
-
Create and Format Single Values
-
Using the addtotals Command
Filtering and Formatting Data
-
Using the eval Command
-
Using the search and where Commands to Filter Calculated Results
-
Using fillnull Command
Correlating Events
-
Identify transactions
-
Group events using fields
-
Group events using fields and time
-
Search with transactions
-
Report on transactions
-
Determine when to use transaction vs. stats
Introduction to Knowledge Objects
-
Identify the Categories of Knowledge Objects
-
Define the role of a Knowledge Manager
-
Identify Naming Conventions
-
Review Permissions
-
Manage Knowledge Objects
-
Describe the Splunk Common Information Model (CIM)
Creating and Managing Fields
-
Review the Field Extractor (FX) Methods
-
Identify the Different Options to get to the Field Extractor
-
Review the Process of Extracting fields Manually Using Regular Expressions
-
Use the Field Extraction Manager to Modify Extracted fields
Creating Field Aliases and Calculated Fields
-
Create and Use Field Aliases
-
Create Calculated Fields
Creating Tags and Event Types
-
Create and Use Tags
-
Describe Event Types and their Uses
-
Create an Event Type
Creating and Using Macros
-
Describe Macros
-
Manage Macros
-
Create a Basic Macro
-
Use a Basic Macro
-
Define Arguments and Variables for a Macro
-
Add and Use Arguments with a Macro
Creating and Using Workflow Actions
-
Create a GET Workflow Action
-
Create a POST Workflow Action
-
Create a Search Workflow Action
Creating Data Models
-
Describe the Relationship between Data Models and Pivot
-
Identify Data Model Datasets
-
Identify Dataset Fields
-
Create a Data Model
-
Use a Data Model in Pivot
Using the Common Information Model (CIM) Add-On
-
Describe the Splunk Common Information Model
-
List the Knowledge Objects Included with the Splunk CIM Add-On
-
Use the CIM Add-On to Normalize Data
Course description
The Splunk Engineering: Intermediate Level is designed for individuals who already have basic understanding of the Splunk architecture as well as Splunk Processing Language (SPL). This course builds on your knowledge from the Splunk Engineering: Beginner Level and introduces you to deeper concepts and terminologies in Splunk.
In this course, you will:
• Use transforming commands and visualizations
• Filter and format the results of a search
• Correlate events into transactions
• Create and manage Knowledge Objects
• Create & manage extracted fields, field aliases, calculated fields
• Create tags and event types
• Create and use macros and workflow objects
• Create and manage data models
• Use the Splunk Common Information Model (CIM).
This Splunk certification training will help you clear the following Certification levels in Splunk.
• Splunk Core Certified Power User
What I will learn?
- In this course, you will become a well-rounded knowledge object developer in Splunk. You will learn new SPL searching and reporting commands, create knowledge objects, use field aliases and calculated fields, create tags and event types, use macros, create workflow actions and data models, and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms.
Material Includes
- Lecture Sheets and Recordings
- PDF Resources
- Useful Links
Requirements
- Laptop: A laptop with at least 8 GB of Memory, 1.8 GHZ of CPU and 250GB of Hard Drive or more.
- Notebook: This is needed to take notes during the lectures and document your questions.
- Passion: Here at JM MiSa training, we believe no true success is void of a drive and will to succeed. This is what makes you stay focused when you encounter obstacles or challenges along the way. Don't worry, our experienced instructors will be there with you all through the way.
Target Audience
- Individuals with basic understanding of the Splunk platform or those who have successfully completed Splunk Engineering: Beginner Level.
A course by
Student Ratings & Reviews

-
LevelIntermediate
-
Duration24 hours
-
Last UpdatedMay 15, 2022
-
CertificateCertificate of completion
Splunk Engineering: Intermediate Level

-
LevelIntermediate
-
Duration24 hours
-
Last UpdatedMay 15, 2022
-
CertificateCertificate of completion
Course Curriculum
Beyond Search Fundamentals
-
Review Basic Search Commands
-
Use Case correctly in Searches
-
Describe Splunk’s Search Process
Commands for Visualizations
-
Explore Data Structure Requirements
-
Explore Visualization Types
-
Create and Format Charts
-
Create and Format Timecharts
-
Explain when to use each type of Reporting Command
Advanced Visualizations
-
Create a Trendline
-
Create Maps
-
Create and Format Single Values
-
Using the addtotals Command
Filtering and Formatting Data
-
Using the eval Command
-
Using the search and where Commands to Filter Calculated Results
-
Using fillnull Command
Correlating Events
-
Identify transactions
-
Group events using fields
-
Group events using fields and time
-
Search with transactions
-
Report on transactions
-
Determine when to use transaction vs. stats
Introduction to Knowledge Objects
-
Identify the Categories of Knowledge Objects
-
Define the role of a Knowledge Manager
-
Identify Naming Conventions
-
Review Permissions
-
Manage Knowledge Objects
-
Describe the Splunk Common Information Model (CIM)
Creating and Managing Fields
-
Review the Field Extractor (FX) Methods
-
Identify the Different Options to get to the Field Extractor
-
Review the Process of Extracting fields Manually Using Regular Expressions
-
Use the Field Extraction Manager to Modify Extracted fields
Creating Field Aliases and Calculated Fields
-
Create and Use Field Aliases
-
Create Calculated Fields
Creating Tags and Event Types
-
Create and Use Tags
-
Describe Event Types and their Uses
-
Create an Event Type
Creating and Using Macros
-
Describe Macros
-
Manage Macros
-
Create a Basic Macro
-
Use a Basic Macro
-
Define Arguments and Variables for a Macro
-
Add and Use Arguments with a Macro
Creating and Using Workflow Actions
-
Create a GET Workflow Action
-
Create a POST Workflow Action
-
Create a Search Workflow Action
Creating Data Models
-
Describe the Relationship between Data Models and Pivot
-
Identify Data Model Datasets
-
Identify Dataset Fields
-
Create a Data Model
-
Use a Data Model in Pivot
Using the Common Information Model (CIM) Add-On
-
Describe the Splunk Common Information Model
-
List the Knowledge Objects Included with the Splunk CIM Add-On
-
Use the CIM Add-On to Normalize Data
Course description
The Splunk Engineering: Intermediate Level is designed for individuals who already have basic understanding of the Splunk architecture as well as Splunk Processing Language (SPL). This course builds on your knowledge from the Splunk Engineering: Beginner Level and introduces you to deeper concepts and terminologies in Splunk.
In this course, you will:
• Use transforming commands and visualizations
• Filter and format the results of a search
• Correlate events into transactions
• Create and manage Knowledge Objects
• Create & manage extracted fields, field aliases, calculated fields
• Create tags and event types
• Create and use macros and workflow objects
• Create and manage data models
• Use the Splunk Common Information Model (CIM).
This Splunk certification training will help you clear the following Certification levels in Splunk.
• Splunk Core Certified Power User
What I will learn?
- In this course, you will become a well-rounded knowledge object developer in Splunk. You will learn new SPL searching and reporting commands, create knowledge objects, use field aliases and calculated fields, create tags and event types, use macros, create workflow actions and data models, and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms.
Material Includes
- Lecture Sheets and Recordings
- PDF Resources
- Useful Links
Requirements
- Laptop: A laptop with at least 8 GB of Memory, 1.8 GHZ of CPU and 250GB of Hard Drive or more.
- Notebook: This is needed to take notes during the lectures and document your questions.
- Passion: Here at JM MiSa training, we believe no true success is void of a drive and will to succeed. This is what makes you stay focused when you encounter obstacles or challenges along the way. Don't worry, our experienced instructors will be there with you all through the way.
Target Audience
- Individuals with basic understanding of the Splunk platform or those who have successfully completed Splunk Engineering: Beginner Level.