top of page

Summary

​

This two-day course focuses on Splunk Enterprise app development. It's designed for advanced users, administrators, and developers who want to create apps for Splunk Enterprise and Splunk Cloud. Major topics include planning apps, building data generators, adding data, custom search commands and REST endpoints, using the KV Store, app vetting using AppInspect and app packaging.

​

Description

  • Planning Apps

  • Creating Apps

  • Adding Data

  • Enhancing Apps

  • Using the REST API

  • Packaging Apps

 

​

​

Splunk Fundamentals 1 - Legacy Course Information

Enjoyable presenter and easy to understand for an intermediate Splunk user pursuing Admin certification. Thanks from Massachusetts!

Participant, Splunk Fundamentals 2

Splunk Credit Value: 150

Duration: 2 days

Time: 11am – 3.30 pm AEST

​

Objectives

​

Module 1 – Planning Apps

  • Set up a development environment

  • Improve app performance

  • Identify Splunk log files

  • Use security best practices

  • Create a data generator

​

Module 2 – Creating Apps

  • Describe the web framework architecture

  • Manage apps and add-ons

  • Create an app

  • Configure app properties

  • Create app navigation

  • Add app icons and logos

​

Module 3 – Adding Data

  • List types of data inputs

  • Identify ways to add data

  • Explain modular vs scripted inputs

  • Understand data normalization

  • Review Add-on Builder

​

Module 4 – Enhancing Apps

  • Review commonly used knowledge object

  • Learn about custom alert actions

  • Build custom workflow actions

  • Develop custom search commands

Module 5 – Using the REST API

  • Describe the Splunk REST API works

  • Explain using REST with SplunkJS

  • Extend Splunk with custom REST endpoints

  • Review the KV Store and configuration

  • Maintain app state using KV Store

​

Module 6 – Packaging Apps

  • Creating an app setup screen

  • Define config file precedence

  • Validate an app for Cloud with AppInspect

  • Explain local and default differences

  • Package an app

 

Prerequisites

​

To be successful, students should have a solid understanding of the following courses:

  • Splunk Fundamentals 1

  • Splunk Fundamentals 2

  • Creating Dashboards

​

OR the following single-subject courses:

  • What Is Splunk?

  • Intro to Splunk

  • Using Fields

  • Visualizations

  • Leveraging Lookups and Subsearches

  • Search Under the Hood

  • Introduction to Knowledge Objects

  • Creating Knowledge Objects

  • Creating Field Extractions

  • Enriching Data with Lookups

  • Introduction to Dashboards

  • Dynamic Dashboards

​

Students should also have completed the following courses:

  • Advanced Dashboards & Visualizations

  • Splunk System Administration (recommended)

Enquiry Form

Let us know what you're after

Thanks for submitting!

CONTACT US (3).png
BOOK NOW.png

Splunk Course Schedules and Timezones

Ingeniq Course are delivered live and in English and provide access to customers spanning multiple timezones.

​

Dates and times displayed for each course are relative to Australian Eastern Time (AET).

​

​

AM Marked Splunk Courses

AM marked courses start at AET 9:00am and finish at AET 1:30pm (4.5 hour sessions over 1 or more days) and are optimal for customers in the following countries and areas;

​

  • UTC+10 including Australia (East Coast)

  • UCT+11/+12 including New Zealand and the Pacific Islands

  • UTC-8 including USA (West Coast), Canada (West Coast)

  • UTC-7 including USA (Mid West)

PM Marked Splunk Courses

PM marked courses start at AEDT 12:00pm and are optimal for customers in the following countries and areas;

​

  • UTC+10 including Australia (East Coast)

  • UCT+11/+12 including New Zealand and the Pacific Islands

  • UTC-8 including USA (West Coast), Canada (West Coast)

  • UTC-7 including USA (Mid West)

bottom of page