This course focuses on searching and reporting commands as well as on the creation of knowledge objects. Major topics include using transforming commands and visualizations, filtering and formatting results, correlating events, creating knowledge objects, using field aliases and calculated fields, creating tags and event types, using macros, creating workflow actions and data models, and normalizing data with the Common Information Model (CIM).
As of Oct. 25, 2021, Splunk Education has replaced this course with the new Single-Subject Courses. Please refer to this page for more information on the new offerings. This course will continue to be offered by our Authorized Learning Partners (ALPs) only until approximately April 30, 2022.
Registration for this course is no longer available.