Splunk Basics Course
Complete hands-on tutorial about the process of logging and monitoring using the amazing and agile tool Splunk

What you will learn

ICT Logging and monitoring basics

How to make logs work for you and get notified if something went wrong

Visualize data received from any log source in very simple steps

Build a small computer LAB that consists of a Splunk server, Apache web server and Fortigate firewall virtual appliance

Install and configure Splunk Enterprise and Splunk Universal Forwarder

Know the different deployment types of Splunk

Collect logs from remote nodes using Splunk Universal Forwarder

Collect logs from Syslog devices like Fortigate firewall

Search and explore data on Splunk

Extract fields and add knowledge to data

Quick introduction to Splunk Search Processing language (SPL)

Description

Machines are trying to tell us something through logs, so they are a very valuable resource for IT departments to ensure that everything is working as expected and to give us an idea of what is going on in our ITย environments which will help to respond faster to incidents.

In this hands-on course, we will learn how to set up a small virtual LAB to simulate real-world logging and monitoring scenarios, where we will collect logs from Apache web server and Fortigate firewall and send them to Splunk for storage, analysis, visualization and alerting.

Iย selected these two log sources specifically because they represent the majority of log sources you will find in your environment, so you can follow the same steps in the course to integrate different log sources in the future.

There are more complex log sources to integrate like logs that are pulled from database but they are not suitable to be discussed in an introductory course.

After we onboard logs to Splunk, we will search and explore data we received then we will add knowledge to it by extracting interesting fields in these logs.


Get Instant Notification of New Courses on our Telegram channel.


At this point, our logs will be ready to be treated by Splunk Searching Processing Language (SPL) to create reports, dashboards, and alerts.

This course will make you ready to dig deep into more advanced topics of Splunk administration like,

  • High availability
  • Indexers clusters
  • Search head clusters
  • Deployments servers
  • Splunk Apps
  • Advanced SPL

But you have to walk before you run, so my vision for this course is to master the basics first to break the ice.

Note:

When the course was recorded Splunk version was 8.0.4.1, On 10-09-2022 I validated Splunk Enterprise 9.0.1 on my own test lab and the steps and instructions in this course still apply.

English
language

Content

Introduction

Introduction to the course
Course structure
Udemy 101: Getting the most from this course

Preparing LAB

Installing VMware Workstation Player
Installing Ubuntu virtual machines
Assign Static IPs to Ubuntu machines and change default password
Downloading Splunk and installing Apache server
Importing Fortigate Appliance

Installing Splunk

Installing Splunk and Splunk Universal Forwarder
Deployment types
Configure Splunk to receive logs

Getting data in

Collecting logs from remote nodes
Configure Syslog source

Searching and exploring logs

Search and explore data on Splunk
Extract fields and add knowledge to data
Splunk Search Processing Language (SPL)

Reporting and monitoring

Creating reports and dashboards
Creating alerts

Keep learning

More to explore
Don’t forget to leave a rating!