Course : Splunk, operational data analysis

Practical course - 3d - 21h00 - Ref. PUK
Price : 2100 € E.T.

Splunk, operational data analysis



Required course

Splunk is a tool that aims to help us collect and sort relevant information: a tool that could be described as [[event correlator]]. This training course will enable you to configure, analyze and generate reports on data based on your personalized alerts.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Disponible en anglais, à la demande

Ref. PUK
  3d - 21h00
2100 € E.T.




Splunk is a tool that aims to help us collect and sort relevant information: a tool that could be described as [[event correlator]]. This training course will enable you to configure, analyze and generate reports on data based on your personalized alerts.


Teaching objectives
At the end of the training, the participant will be able to:
Use Splunk to collect, analyze and report on data
Enrich operational data with searches and feeds
Create real-time, scripted and other intelligent alerts
Integrating advanced JavaScript graphics
Using the Splunk API

Intended audience
System and network administrators.

Prerequisites
Basic knowledge of networks and systems.

Course schedule

1
Configuring Splunk

  • Obtain a Splunk.com account.
  • Install Splunk under Windows.
  • Index files and directories via Web interface, CLI or configuration files.
  • Obtain data via network ports, script or modular inputs.
  • Implementation of the Universal Forwarder.
Hands-on work
Configure Splunk. Implement definition of field extractions, event types and labels.

2
Data mining

  • SPL queries. Boolean operators, commands.
  • Search using time ranges.
Hands-on work
Extract from log files, the most frequently visited Web pages, the most frequently used browser, the most frequently visited sites...

3
Dashboards

  • Dashboards and operational intelligence, making data stand out. Types of graphs.
Hands-on work
Create and enhance a dashboard with graphs linked to searches carried out.

4
New application

  • Install an existing Splunk or third-party application.
  • Add dashboards and searches to an application.
  • Interactive dashboards.
  • Produce regular (scheduled) dashboards in PDF format.
Hands-on work
Create a new Splunk application. Install an application and view events related to Cisco switches.

5
Data models

  • Data models.
  • Take advantage of regular expressions.
  • Optimize search performance.
  • Rotate data.
Hands-on work
Use the template pivot command to display data.

6
Data enrichment

  • Group related events, notion of transaction.
  • Take advantage of multiple data sources.
  • Identify relationships between fields.
  • Predict future values.
  • Discover abnormal values.
Hands-on work
Practice in-depth database searches.

7
Alert types

  • Supervised conditions.
  • Action taken in response to alerts.
  • Become proactive with alerts.
Hands-on work
Execute a script when the Web server error 503 occurs, writing the details associated with the event to a file.


Customer reviews
4,4 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
AYMERIC P.
01/06/26
4 / 5

The training course could do with an update. It was clear that the trainer hadn’t delivered this course for some time without revising it. He wasted time looking up details he had forgotten. Furthermore, some practical exercises were no longer working properly due to changes in Splunk version 10; clearly, the course had been designed for version 9.
AURORE M.
01/06/26
5 / 5

There are a few minor improvements to be made to the practical sessions, particularly the dashboard section. Perhaps we could spend a little less time on the theoretical aspects of the tool and a little more time on the practical sessions.
MARIE EMMANUELLE R.
25/03/26
5 / 5

The content is very interesting and strikes a great balance between theory and practice, which makes the course highly interactive. This balance ensures you never lose focus and remain engaged with the course without feeling lost. The trainer is an excellent teacher. He explains things very clearly and takes the time needed to answer all the questions so that nobody is left behind. What’s more, the content seems practical for use afterwards. It’s a course I would recommend 100 per cent.



Publication date : 01/15/2024



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 16 Sep., 2 Dec.

2027 : 10 Mar., 10 Mar., 23 June, 23 June, 22 Sep., 22 Sep., 15 Nov., 15 Nov.

PARIS LA DÉFENSE
2026 : 16 Sep., 2 Dec.

2027 : 10 Mar., 23 June, 22 Sep., 15 Nov.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.