Troubleshooting Splunk Enterprise (TSE)

It covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available with Splunk Enterprise. This lab-oriented class is designed to help you gain troubleshooting experience before attending more advanced courses. You will debug a distributed Splunk Enterprise environment using the live system. This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or Splunk premium apps.

Retail Price: $1,000.00

Next Date: Request Date

Course Days: 1


Request a Date

Request Custom Course


Course Objectives

  • Splunk Troubleshooting Methods and Tools
  • Indexing Problems
  • Input Configuration Problems
  • Deployment Problems
  • License, Upgrade, and User Management Problems
  • Search Management Problems
  • User Search Problems
  • Understand the Splunk Support Model and its resources
  • Identify the best practices for troubleshooting Splunk Enterprise
  • List ways to gather useful Splunk diagnostic information
  • Use Splunk diagnostic tools
  • Identify common Splunk technical issues and solve them

Who should attend

This 9-hour course is designed for Splunk administrators.

Prerequisites

To be successful, students should have a solid understanding of the following courses:

  • Splunk Fundamentals 1
  • Splunk Fundamentals 2

Student should also have completed the following courses:

  • Splunk Enterprise System Administration (SESA)
  • Splunk Enterprise Data Administration (SEDA)

Outline: Troubleshooting Splunk Enterprise (TSE)

Module 1 – Splunk Troubleshooting Methods and Tools

  • Describe the Splunk Troubleshooting Approach
  • List Splunk Diagnostic Resources and Tools
  • Create and Splunk a Diag
  • Use RapidDiag

Module 2 – Indexing Problems

  • Discover Splunk Deployment Topology and its Server Roles
  • Identify Where to Check the Index-Time Pipeline Status
  • Use the metrics.log to Clarify the Index-Time Problem

Module 3 – Input Configuration Problems

  • Data Input Issues
  • Troubleshooting Inputs with the Monitoring Console

Module 4 – Input Configuration Problems

  • Deployment Server Issues
  • Forwarding and Receiving Issues

Module 5 – Indexer Cluster Management Administration

  • Peer Offline and Decommission
  • Master App Bundles
  • Indexer Cluster Storage Utilization Options
  • Site Mapping
  • Monitoring Console for Indexer Cluster Environment

Module 6 – License, Upgrade, and User Management Problems

  • Installation Issues
  • Upgrade Considerations
  • Splunk Licensing Issues
  • Splunk Roles and User Management Issues

Module 7 – Search Head Management Problems

  • Troubleshoot Distributed Search Issues
  • Identify Job Scheduling Problems
  • Learn to Diagnose Crashing Problems
  • Describe How to Prioritize Resources for Critical Splunk Processes

Module 8 – KV Store Collection and Lookup Management

  • Identify the Types of Search Problems
  • Isolate and Troubleshoot Search Problems


Sorry! It looks like we haven’t updated our dates for the class you selected yet. There’s a quick way to find out. Contact us at 502.265.3057 or email info@training4it.com


Request a Date