Course Description

This two-day course is designed for power users who want to create fast and efficient views that include customized charts, drilldowns, advanced behaviors and visualizations. Major topics include using tokens, global searches, event handlers, dynamic drilldowns and simple XML extensions for JavaScript and CSS.

Instructor-led Training Schedule

Course Prerequisites


  • Splunk Fundamentals 1
  • Splunk Fundamentals 2


  • Working knowledge of XML


  • Experience with CSS and JavaScript


Course Topics

  • Prototyping
  • Using Tokens
  • Improving Performance
  • Customizing Views
  • Using Event Handlers
  • Adding Simple XML Extensions
Course Objectives

Module 1 – Creating a Prototype

  • Define simple syntax for views
  • Use best practices for creating views
  • Identify transforming commands
  • Troubleshoot views

Module 2 – Using Forms

  • Explain how tokens work
  • Use tokens with form inputs 
  • Define types of token filters
  • Create cascading inputs

Module 3 – Improving Performance

  • Identify ways to improve dashboard performance
  • Use the tstats command
  • Use global searches
  • Accelerate data models

Module 4 – Customizing Dashboards

  • Customize chart and panel properties
  • Set panel refresh and delay times
  • Disable search access features

Module 5 – Using Event Handlers

  • Identify types of event handlers
  • Describe event actions
  • Use conditional matching
  • Create an event handler

Module 6 – Adding Drilldowns

  • Define types of drilldowns
  • Identify predefined tokens
  • Create dynamic drilldowns 
  • Create contextual drilldowns

Module 7 – Adding Advanced Visualizations & Behaviors

  • Use simple XML extensions
  • Define Splunk custom visualizations 
  • Troubleshoot simple XML extensions