Troubleshooting Splunk Enterprise

This 2-virtual day course is designed for Splunk administrators. It covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available on Splunk Enterprise 6.6.

It is a lab-oriented class designed to help you gain troubleshooting experience before attending more advanced courses. You will debug a distributed Splunk Enterprise environment using the live system and simulated case logs.

This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or Splunk premium apps.

View schedule »

Download course description »

Upcoming Classes

Course Topics

  • Splunk Support Model
  • Splunk Troubleshooting Methods and Tools
  • Clarifying the Problem
  • Installation, Licensing, and Crash Problems
  • UI and Search Problems
  • Configuration Problems
  • Deployment Problems
  • User Management Problems

Course Prerequisites

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2
  • Splunk Data Administration
  • Splunk System Administration

Class Format

Instructor-led lecture with labs. Delivered via virtual classroom or at your site.

Course Modules

Module 1 - Splunk Support Model

  • Splunk support resources

Module 2 - Splunk Troubleshooting Methods and Tools

  • Splunk troubleshooting methodology
  • Splunk diagnostic tools

Module 3 - Clarifying the Problem

  • Splunk Topology
  • Index-time pipeline
  • Search-time pipeline

Module 4 - Installation, Licensing, and Crash Problems

  • Installation issues
  • License issues
  • Crash issues

Module 5 - Configuration Problems

  • Input issues
  • Configuration Precedence

Module 6 - UI and Search Problems

  • Search issues
  • Dashboard issues

Module 7 - Deployment Problems

  • Forwarding issues
  • Distributed search issues
  • Deployment server issues

Module 8 - User Management Problems

  • Splunk users and role capabilities
  • Directory integration issues