Skip to main content
  • Book
  • © 2021

Splunk Certified Study Guide

Prepare for the User, Power User, and Enterprise Admin Certifications

Apress

Authors:

  • Includes multiple choice questions in every chapter
  • Discusses best practices in Splunk
  • Covers techniques that will help Splunk admins to troubleshoot Splunk Enterprise
  • 11k Accesses

Buy it now

Buying options

eBook USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access

This is a preview of subscription content, log in via an institution to check for access.

Table of contents (18 chapters)

  1. Front Matter

    Pages i-xxv
  2. Splunk Architecture, Splunk SPL (Search Processing Language), and Splunk Knowledge Objects

    1. Front Matter

      Pages 1-1
    2. An Overview of Splunk

      • Deep Mehta
      Pages 3-26
    3. Splunk Search Processing Language

      • Deep Mehta
      Pages 27-52
    4. Tags, Lookups, and Correlating Events

      • Deep Mehta
      Pages 75-99
    5. Data Models, Pivot, and CIM

      • Deep Mehta
      Pages 101-123
    6. Splunk User/Power User Exam Set

      • Deep Mehta
      Pages 155-160
  3. Splunk Data Administration and System Administration

    1. Front Matter

      Pages 161-161
    2. Advanced Data Input in Splunk

      • Deep Mehta
      Pages 213-241
    3. Splunk’s Advanced .conf File and Diag

      • Deep Mehta
      Pages 243-265
    4. Splunk Admin Exam Set

      • Deep Mehta
      Pages 267-272
  4. Advanced Splunk

    1. Front Matter

      Pages 273-273
    2. Troubleshooting in Splunk

      • Deep Mehta
      Pages 317-341
    3. Advanced Deployment in Splunk

      • Deep Mehta
      Pages 343-364
    4. Advanced Splunk

      • Deep Mehta
      Pages 365-387

About this book

Make your Splunk certification easier with this exam study guide that covers the User, Power User, and Enterprise Admin certifications. This book is divided into three parts. The first part focuses on the Splunk User and Power User certifications starting with how to install Splunk, Splunk Processing Language (SPL), field extraction, field aliases and macros, and Splunk tags. You will be able to make your own data model and prepare an advanced dashboard in Splunk.

In the second part, you will explore the Splunk Admin certification. There will be in-depth coverage of Splunk licenses and user role management, and how to configure Splunk forwarders, indexer clustering, and the security policy of Splunk. You’ll also explore advanced data input options in Splunk as well as .conf file merging logic, btool, various attributes, stanza types, editing advanced data inputs through the .conf file, and various other types of .conf file in Splunk.

The concluding part covers the advanced topics of the Splunk Admin certification. You will also learn to troubleshoot Splunk and to manage existing Splunk infrastructure. You will understand how to configure search head, multi-site indexer clustering, and search peers besides exploring how to troubleshoot Splunk Enterprise using the monitoring console and matrix.log. This part will also include search issues and configuration issues. You will learn to deploy an app through a deployment server on your client’s instance, create a server class, and carry out load balancing, socks proxy, and indexer discovery.

By the end of the Splunk Certified Study Guide, you will have learned how to manage resources in Splunk and how to use REST API services for Splunk. This section also explains how to set up Splunk Enterprise on the AWS platform and some of the best practices to make them work efficiently together.

The book offers multiple choice question tests for each part that will help you better prepare for the exam.

What You Will Learn

  • Study to pass the Splunk User, Power User, and Admin certificate exams
  • Implement and manage Splunk multi-site clustering
  • Design, implement, and manage a complex Splunk Enterprise solution
  • Master the roles of Splunk Admin and troubleshooting
  • Configure Splunk using AWS

Who This Book Is For

People looking to pass the User, Power User, and Enterprise Admin exams. It is also useful for Splunk administrators and support engineers for managing an existing deployment.


Authors and Affiliations

  • Printserv, Mumbai, India

    Deep Mehta

About the author

Deep Mehta is a AWS Certified Associate Architect, Docker Certified Associate, Certified Splunk Architect (ongoing), and Certified Splunk User, Power User, and Admin. He’s worked on the Splunk platform since 2017 having experience consulting in the telecommunication, aviation, and healthcare industries. Apart from being passionate about big data technologies, he also loves playing squash and badminton.

Bibliographic Information

Buy it now

Buying options

eBook USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access