EQALIS APPSTORE

 

EQALIS Symantec Virus Log App

Allows users of Symantec Anti-Virus 2009 software to use Splunk to index, search and report on its logs.

 

View

VIDEOS

 

January 21st, 2013

Cars.com Revs up ROI with Splunk Software

Cars.com and Splunk boost ROI - Video Casestudy

 

View

BLOG

 

May 3rd, 2013

Splunk buzz at Infosec 2013

The buzz around Splunk was heightened by the presentation of the Best Enterprise Security Solution Award by SC Magazine at the SC Magazine Awards Europe on the opening evening.

 

View

Call Us - 0845 643 9180

Administering Splunk 5.0

 

This eight hour course prepares system administrators to configure and manage Splunk. It covers installation, configuring data inputs and forwarders, data management, user accounts, licenses, and basic troubleshooting and monitoring. It's recommended for systems administrators responsible for the day-to-day administration of Splunk.

 

Course Topics

  • Typical Splunk installations

  • Apps and technology add-ons

  • Common methods of data input

  • Splunk forwarders' role in data inputs

  • Default input processing and common configurations

  • Managing Splunk data stores

  • Configuring groups, users, and data security

  • Managing and installing Splunk licenses

  • Troubleshooting a Splunk instal

  • lBest practices for upgrading Splunk

 

Class Format 

As Above.

 

Prerequisites

Using Splunk

 

Course Objectives

 

Lesson 1 - Setting Up Splunk

  • Describe typical Splunk installs

  • Install Splunk

  • Perform server basics including starting, stopping, and restarting Splunk

 

Lesson 2 - Getting Data In

  • Identify how to get data into Splunk

  • Set up inputs using Apps

  • Set input properties such as host, ports, index, source type, etc.

 

Lesson 3 - Data Inputs

  • Manually specify data inputs

  • List Splunk's data input types and explain how they diffe

  • Set input properties such as host, ports, index, source type, etc

 

Lesson 4 - Windows Inputs 

  • Understand Windows-specific data

  • Configure Windows specific inputs

 

Lesson 5 - Forwarders

  • Compare forwarder types

  • Understand forwarder benefits

  • Deploy and configure forwarders

 

Lesson 6 - Understanding Data Processing

  • Describe how data moves through Splunk

  • Set source type

  • Understand how Splunk sets time zones

  • Configure search-time field extraction 

 

Lesson 7 - Splunk's Data Store

  • Set up indexes

  • Describe back up strategies

  • Set archived data parameters

  • Restore archived data

 

Lesson 8 - Users, Roles, and Authentication

  • Understand user roles in Splunk

  • Create a custom role

  • Understand the delete role

 

Lesson 9 - Licensing 

  • Identify license types

  • Understand license violations

  • Define license groups, license pooling and stacking

  • Add and remove licenses

 

Lesson 10 - Housekeeping

  • Describe jobs and job management

  • Understand alerts, and alert settings

  • Understand knowledge objects and their permissions

  • Describe troubleshooting best practices

  • Identify where to get help

 

Lesson 11 - Upgrading Splunk

  • Understand Splunk's update mode

  • Identify where to look for Splunk update notifications

  • Describe the recommended steps to upgrade Splunk 

 

Find Out More


 
22.04.2013

Using Splunk

Go »

22.04.2013

Searching and Reporting with Splunk 5.0

Go »

24.04.2013

Advanced Splunk Administration

Advanced Splunk Administration

Go »

29.04.2013

Architecting and Deploying Splunk 5.0

Architecting and deploying Splunk 5.0

Go »

01.05.2013

Developing Apps with Splunk

Developing Apps with Splunk

Go »

View All
 
Videos

VIDEOS

Selection of videos from our youtube channel
Blog

BLOG

EQALIS has gained its edge by continually seeking out new life in the IT management, IT compliance and IT security product fields to help organisations challenge their current approaches.
Product Trials

PRODUCT TRIALS

Splunk & PCI Compliance - Whitepaper
A Whitepaper describing how to map Splunk Enterprise to support your PCI requirements.
View All