When you enroll in this course, you'll also be enrolled in this Specialization.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate
There are 4 modules in this course
In this course, you will learn how to calculate co-occurrence between fields and analyze data from multiple datasets, increase your knowledge of searching and learn how to work with multivalue data. In addition, you will learn tips and tricks to improve search performance using accelerations.
This module is for users who want to learn how to calculate co-occurrence between fields and analyze data from multiple datasets. Topics will focus on the transaction, append, appendcols, union, and join commands.
What's included
10 videos2 readings1 assignment
Show info about module content
10 videos•Total 52 minutes
Understanding Transactions•2 minutes
Transaction Command•8 minutes
Working with Transactions•10 minutes
Complete and Incomplete Transactions•7 minutes
Optimizing Transactions•4 minutes
Introduction to Subsearch•10 minutes
Append Command•4 minutes
Appendcols Command•2 minutes
Join Command•3 minutes
Union Command•3 minutes
2 readings•Total 10 minutes
Learning Objectives•5 minutes
Lesson Notes•5 minutes
1 assignment•Total 5 minutes
Correlation Analysis•5 minutes
Search Under the Hood
Module 2•1 hour to complete
Module details
This eLearning module gives students additional insight into how Splunk processes searches. Students will learn about Splunk architecture, how components of a search are broken down and distributed across the pipeline, and how to troubleshoot searches when results are not returning as expected.
What's included
9 videos2 readings1 assignment
Show info about module content
9 videos•Total 48 minutes
Introduction•0 minutes
Using the Search Job Inspector•8 minutes
SPL Commenting•4 minutes
Splunk Architecture•6 minutes
Streaming vs. Non-Streaming Commands•4 minutes
Breakers and Segmentation•10 minutes
Makeresults Command•4 minutes
Fieldsummary Command•8 minutes
Informational Functions•4 minutes
2 readings•Total 10 minutes
Learning Objectives•5 minutes
Lesson Notes•5 minutes
1 assignment•Total 5 minutes
Search Under the Hood•5 minutes
Multivalve Fields
Module 3•1 hour to complete
Module details
This module is for users who want to become experts on searching and manipulating multivalue data. Topics will focus on using multivalue eval functions and multivalue commands to create, evaluate, and analyze multivalue data.
What's included
20 videos2 readings1 assignment
Show info about module content
20 videos•Total 67 minutes
Introduction•0 minutes
What are multivalue fields?•8 minutes
Spath Command•14 minutes
Spath Function•1 minute
Multikv Command•5 minutes
List Function•2 minutes
Values Function•1 minute
Transaction Command•2 minutes
Creating Multivalue Fields•1 minute
Split Function•3 minutes
Makemv Command•5 minutes
Evaluating Multivalue Fields•3 minutes
Mvindex Function•4 minutes
Mvfilter Function•2 minutes
Manipulating Multivalue Data•3 minutes
Mvzip Function•4 minutes
Mvjoin Function•1 minute
Mvmap Function•1 minute
Mvappend Function•3 minutes
Mvexpand Command•3 minutes
2 readings•Total 10 minutes
Learning Objectives•5 minutes
Lesson Notes•5 minutes
1 assignment•Total 5 minutes
New Quiz•5 minutes
Search Optimization
Module 4•1 hour to complete
Module details
This module is for users who want to improve search performance. Topics will cover how search modes affect performance, how to create an efficient basic search, how to accelerate reports and data models, and how to use the tstats command to quickly query data.
What's included
7 videos2 readings1 assignment
Show info about module content
7 videos•Total 52 minutes
Search Optimization Overview•3 minutes
Splunk Search Scheduler•2 minutes
Search Acceleration Overview•2 minutes
Report Acceleration •7 minutes
Data Model Acceleration•6 minutes
Datamodel Command•13 minutes
Tstats Command•20 minutes
2 readings•Total 15 minutes
Learning Objectives•5 minutes
Lesson Notes•10 minutes
1 assignment•Total 5 minutes
Search Optimization•5 minutes
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor
Instructor ratings
Instructor ratings
We asked all learners to give feedback on our instructors based on the quality of their teaching style.
The Splunk platform is designed to remove the barriers between data and action, so that everyone thrives in the Data Age. We’re empowering IT, DevOps and security teams to transform their organizations with data from any source and on any timescale.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.