Skip to main content

Splunk Training + Certification

Troubleshooting Splunk Enterprise

Course Description

This 2 day virtual course is designed for Splunk administrators. It covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available on Splunk Enterprise.


It is a lab-oriented class designed to help you gain troubleshooting experience before attending more advanced courses. You will debug a distributed Splunk Enterprise environment using the live system and simulated case logs.


This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or Splunk premium apps.


Instructor-led Training Schedule

Course Prerequisites

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2
  • Splunk Data Administration
  • Splunk System Administration

Course Topics

  • Splunk Troubleshooting Methods and Tools
  • Indexing Problems
  • Input Configuration Problems
  • Deployment Problems
  • License, Upgrade, and User Management Problems
  • Search Management Problems
  • User Search Problems

Course Objectives

Module 1 – Splunk Troubleshooting Methods and Tools
  • Splunk support resources
  • Splunk troubleshooting approach
  • Splunk diagnostic resources and tools
Module 2 – Indexing Problems
  • Splunk deployment topology
  • Index-time pipeline
  • Metrics.log
Module 3 – Input Configuration Problems
  • Input issues
  • Monitoring console
Module 4 – Deployment Problems
  • Deployment server issues
  • Forwarding and receiving issues
Module 5 – License, Upgrade, and User Management Problems
  • Installation issues
  • Upgrade considerations
  • Splunk licensing issues
  • Directory integration issues
  • Splunk Roles and User Management issues
Module 6 – Search Management Problems
  • Distributed search issues
  • Knowledge bundle replication issues
  • Job scheduling issues
  • Splunk crash issues
  • Splunk workload management
Module 7 – User Search Problems
  • Search issues
  • Troubleshooting search with Job Inspector