Best Seller!
SPLK-1002: Splunk Core Certified Power User

SPLK-1002: Splunk Core Certified Power User Certification Video Training Course

SPLK-1002: Splunk Core Certified Power User Certification Video Training Course includes 187 Lectures which proven in-depth knowledge on all key concepts of the exam. Pass your exam easily and learn everything you need with our SPLK-1002: Splunk Core Certified Power User Certification Training Video Course.

145 Students Enrolled
187 Lectures
15:54:00 hr

Curriculum for Splunk SPLK-1002 Certification Video Training Course

SPLK-1002: Splunk Core Certified Power User Certification Video Training Course Info:

The Complete Course from ExamCollection industry leading experts to help you prepare and provides the full 360 solution for self prep including SPLK-1002: Splunk Core Certified Power User Certification Video Training Course, Practice Test Questions and Answers, Study Guide & Exam Dumps.

Introduction to Splunk Enterprise

26. Getting Help on Splunk Issues : Part 1

Now we are already committed to understanding Splunk and becoming Splunk masters. We will see how we can get help when we get stuck at any stage of Splunk learning or implementation or operations. The first option for help, as we saw earlier, was on the Splunk GUI. We have seen this earlier, which lists all the resources necessary for learning or troubleshooting Splunk. The second and probably the bestplace is the Splunk Answers. That is the answer at We know by now that it is kind of a stack overflow for Splunk-related queries, which is a highly active community where a lot of people contribute to exchange and share knowledge. And the third is the Splunk IRC channel. I'll just quickly show you how you can use Splunk's IRC channel. It is basically on EFNet. Let me type in just Efnet. This is an IRC channel where Aztec Splunk is your Splunk channel. Just give whatever name you want and click "Login." It will be connecting to the Splunk channel. There are a lot of Splunk gurus, and you'll probably get faster responses. It will be similar to a chatting application where you can ask questions, type something in, and send it, and someone will respond about Splunk or what is the latest version, any bugs they have discovered, what the issues are, how to troubleshoot, or how to configure a few things. A lot of these people are highly active during US business hours. Rest of the time, it is kind of slow, but Splunk answers on the other side. You will get answers to your queries at any moment during that time. Let me log out of IRC, and we'll go back to our slides. Now we have seen Splunk's IRC channel. The next is the Splunk documentation, which is the best and most accurate place for learning or troubleshooting about Splunk. Probably not for troubleshooting when learning Splunk because most of the documentation is open and available publicly for everyone. It is at If you are looking for Splunk Enterprise, it is at Dot me type it for you. documentation will take you directly to the Splunk Enterprise. If you want to just click on Splunk Enterprise, just type in Docs'll be taken to Splunk Enterprise. Click on this core product, Splunk Enterprise. You'll be taken to all the documentation that's related to Splunk Enterprise. You'll get accurate information that's most efficient, and it's totally free. You can download any manual whichever you want inthe form of PDF or you can download byselecting specific topic and downloading them as PDF. The most important one, which I keep handy every time, is the Search and Reporting Search Reference Manual, because I can't remember the 140-plus commands. I use this manual to quickly search for the syntax of the commands or which commands best fit my present requirement. The second one, which I usually follow, is the admin manual. These two will be my two tabs in my operations every day because you'll get this good menu called Configuration File Reference with examples of syntax that needs to be configured and a short description of what each configuration file is. You can find all this in your Splunk package, which you have downloaded for installation. But I feel this example menu, which shows what it does and what information it contains, will be highly resourceful during the implementation or configuration. This is the admin manualand configuration file reference. The second one, which I use most commonly, is the search reference, which again has search commands. Since we saw the top command in our previous video, these are 140 or more commands. What do I do if I want to know more about Top? I search for top. Click on that command and it will display me. complete syntax, a small description, and examples of that comment, which is huge for learning. Plugging and troubleshooting spark You can see any comments that are practicallyin this product in terms for free. This documentation site is the most accurate, and you probably should make the best use of this documentation. Let's go back to our slides. So the next one is Splunk support. That is, of course, the paid support that comes as part of your license. If you're stuck and there is a business disruption or business impact that's happening, you're not able to resolve the issue. You can raise a call with Splunk by calling them, emailing them, or using your customer portal. You can log in and respond back to you onthe best possible way, that is with the Splunk support. But my experience working on this product is that 80% of the time, you'll find answers from the documentation side or Splunk These two are your best friendsfor learning Splunk or Troubleshooting Splunk. If you can't find answers in these two portals, it's probably a product bug, in which case Splunk support will come into play to identify the bug or provide a workspace for it. Information can be obtained at and Docs.Dot should be able to resolve your issues regarding implementation or learning.

27. Getting Help on Splunk Issues : Part 2

The Splunk Base is the final option for getting assistance. The Splunk base is the place where we download all the add-ons or apps that are necessary for Splunk to add more values. We can find the configurations related to those apps and also troubleshooting information and a complete guide to those applications. right next to the app that we are downloading. Let's see one of the examples, which is App Store it has been renamed to "Splunk-based," but I'm used to typing apps dot Let me search for or find some app that I can easily get through. Let's see the machine learning app and how we can get more information, like configuration or documentation, on what the app does. So this is the place where you can get help. There is a YouTube playlist for this channel that's awesome. There is a cheat sheet, and they put in enough effort to make this stuff available. There are details, which include documentation sites, the requirements, and how to install. These are the details that you can get from Splunk Base regarding applications or add-ons.

28. Get 10 GB Free license of Splunk

After learning all this introduction about Splunk and its components, products, the basic UI, how it looks, everything, Now we will see how we can get a free licence from Splunk. Yes, we will get 500 MB of free licence as part of our installation package. But we can get developer licences for free. All you need to do is just click on this link, and it will take you right into the form where you need to submit or log into the portal. if you have not already logged in. As soon as this link loads, if you are not logged in, it will ask you to login. You can log in. You can click on "Request for Developer License. That's it. You'll get your ten GB free license, which is valid for six months and is not commercial. You are not authorised to sell it. With this 10 GB license, you can use it for learning purposes or you can use it to build your own environment. These are the kinds of experiments you can do using your license. After this course, you'll probably be able to develop technology-specific apps. Let's say some of you might be working in big data, some of you might be working in security, some might be working in the health industry, and some of you might be working in banking. Let's say you develop an app specific to your industry that is working fantastically in your organization. You can upload it to Splunk Base and get it approved. It will be approved, probably within a matter of days. And once it is published, you can apply for 50 GB of daily licence limit, which is really good for learning Splunk or building Splunk apps. It's 50 GB. A lot of companies won't have a 50 GB license, but having an individual 50 GB licence can give you more access for learning Splunk and experimenting with more data and getting in different data sources together. You can probably create an entire AWS or Google cloud environment with a list of your own bare-metal instances.

Designing Splunk Architecture

1. Splunk Visio Stencils usage

Designing splunk. ArchitectureLearning about Splunk design before implementing our enterprise-level high availability multi-site clustering is essential because you will have a clear understanding of the size of the environment we will be implementing as part of our tutorial. Trust me, it will be one of those things where you can say it is like you have implemented this implementation because you will be part of each and every step, right from the beginning of designing the architecture until the time we complete it and publish it on the Amazon Web Services (AWS) cloud. Before jumping onto designing completely thearchitecture, we need to understand thatarchitecture design without a proper representationwill not have effective impact. To make Splunk architecture design impactful, we willhave to do couple of preparation work likehaving visual installed and making sure that wehave visual tools installed and what each iconmeans to understand Splunk visual utensils. Or you can say that icons would have to go first. Let us download our vision stencils. Go to the link first link. It is nothing but a wiki page. The second link is more descriptive, and it explains the components of those stencils. It's a PDF document. Yes. In the first link, we can see its Splunk visuals. It is in the Splunk wiki, where it has been published and you can download. You can see there are a lot of components listed. Probably you might not pick it up now,but once we have done with our finalcourse of publishing our enterprise architecture of Splunkon AWS, you'll be able to understand this. Most of these components are listed on these Visio stencils. We'll download the Visio stances that it's downloading, and we'll go to, I believe, page number six of the icon collection. You'll be able to see all the icons within those videos and what each icon represents. They've covered nearly everything Splunk Architect would require to create an architect diagram. They are covered in almost every corner of Splunk implementation, considering the batch, file input indexer, indexer clustering deployment, server, cluster master licence manager, and all the components, including the heavy order based on the OS level (as you can see here, every four orders for Windows, Mac, and Linux). These guys have put in a lot of effort in publishing this. But this has added a real quality to creating the architecture. Let me open up my Visio. I'll create a blank drawing, and we have downloaded stencils to add them. Click on more shapes, open stencils in Splunk documentation, or you need to unzip those files. Since I have already unzipped, this is the location where I can click and click on "Open." It will automatically add all your Splunk documentation icons. As you can see here. Let me expand it. See here. You'll be able to see all different types of components using the architecture. Let me demonstrate how simple it is to create and Splunk architecture with VGO. I am a user, and my Spunk architecture I'll create one simple architecture while keeping some minor details in mind. Let's say a 10-GB licence size I'll have a couple of searches—not quite ten gigabytes, let's say it is a medium size. a couple of firewalls sending logs; let me add one more firewall Where are my indexes? I've had my searches; I'll add a couple of indexes; this is one index; this is a group of indexes, so we can consider them as multiple indexes; what else do I need? Probably avoid it I'll add one forwarder, which is our universal forwarder client. I'll have one Linux forwarder and one Mac forwarder. These are nothing but the agents that are sitting on these servers, like this is generic and this is for Linux. This is for Mac, and we will add our Windows forwarder; also, it's a group of forwarders, usually the data sources you can represent as one block; let me put a container there, or I'll put everything under one container and call this my forwards; that's it. Job done, so all this will send, let me pull out a couple of arrow marks, use whichever you feel most comfortable with, not the two sides, I'll use the one side. Because the forwarder is sending logs to my indexer, I'll create a rough one. I already created a couple of architectures; we'll go through them one by one, and I'll create one for my searcher. This will be a two-way process because searched searches and your index responds with the results similarly. There will be a two way from the user when Isay Two-way is like a visual representation of the data you are squaring, and he's getting a response in visualization. This is the typical architecture. I know this looks ugly.

2. Estimation of License required

It's much more efficient and meaningful to create with Splunk icons. For this exercise, I've considered three scenarios: small enterprise, medium enterprise, and large enterprise. And the last one is the crazy one, which involves high availability and clustering architecture. We'll go through them one by one. Before going to that, we have a few more things to sort out. Let's learn those things. That is the licence calculation, which is one of the crucial things in designing any architecture. The crucial step of any Splunk implementation—and when I say any Splunk, it can be small, medium, or large enterprise—is to estimate how much licence you need. This is by far the most difficult step in designing the architecture because there is no straight answer like "I need 100 GB to 100 GB." There can never be a straight answer for how much data we are estimating from data sources because, as we all know, in some scenarios there will be logs because of an error or an application crashing. We'll see how we can best estimate lot size in our environment. This step as a Splunk admin or architect needs you to interact with other teams and ask them what the log size or the data size was yesterday. If they provide a good service. Next, ask them how many devices should be integrated with your Splunk. You will get a rough estimate. Keep that number. It's not over yet. You got it from one team. Repeat the same step with other teams in the organization, like network for the Syslog inputs, flatfiles for either the system team or several teams for their data, and even the database team. After adding up all the numbers, let's say you come to the conclusion of 100 GB of data per day data.But based on my experience, it's better not to go by the exact figure of what we have calculated; it's good to take a 10% to 20% buffer so that any spiking logs should be manageable and should be well under our limit. Now, to conclude, after discussing and agreeing with all the teams, we can come to a rough estimate of probably 120 GB of data, including a buffer.

Read More

Download Free Splunk SPLK-1002 Practice Test Questions, Splunk SPLK-1002 Exam Dumps

File Votes Size Last Comment 1 320.94 KB 2 36.27 KB 3 208.66 KB  
208.66 KB
Last Comment
* The most recent comment are at the top

Add Comments

Feel Free to Post Your Comments About EamCollection's Splunk SPLK-1002 Certification Video Training Course which Include Splunk SPLK-1002 Exam Dumps, Practice Test Questions & Answers.

Only Registered Members Can Download VCE Files or View Training Courses

Please fill out your email address below in order to Download VCE files or view Training Courses. Registration is Free and Easy - you simply need to provide an email address.

  • Trusted By 1.2M IT Certification Candidates Every Month
  • VCE Files Simulate Real Exam Environment
  • Instant Download After Registration.
Please provide a correct e-mail address
A confirmation link will be sent to this email address to verify your login.
Already Member? Click Here to Login

Log into your ExamCollection Account

Please Log In to download VCE file or view Training Course

Please provide a correct E-mail address

Please provide your Password (min. 6 characters)

Only registered members can download vce files or view training courses.

Registration is free and easy - just provide your E-mail address. Click Here to Register


ExamCollection Premium

ExamCollection Premium Files

Pass your Exam with ExamCollection's PREMIUM files!

  • ExamCollection Certified Safe Files
  • Guaranteed to have ACTUAL Exam Questions
  • Up-to-Date Exam Study Material - Verified by Experts
  • Instant Downloads
Enter Your Email Address to Receive Your 10% Off Discount Code
A Confirmation Link will be sent to this email address to verify your login
We value your privacy. We will not rent or sell your email address


Use Discount Code:


A confirmation link was sent to your e-mail.
Please check your mailbox for a message from and follow the directions.


Download Free Demo of VCE Exam Simulator

Experience Avanset VCE Exam Simulator for yourself.

Simply submit your e-mail address below to get started with our interactive software demo of your free trial.

Free Demo Limits: In the demo version you will be able to access only first 5 questions from exam.