HOME > IT & Software > Splunk Basics Course

Splunk Basics Course

SynopsisSplunk Basics Course, available at Free, has an average ratin...
Splunk Basics Course  No.1

Splunk Basics Course, available at Free, has an average rating of 4.61, with 20 lectures, based on 196 reviews, and has 9408 subscribers.

You will learn about ICT Logging and monitoring basics How to make logs work for you and get notified if something went wrong Visualize data received from any log source in very simple steps Build a small computer LAB that consists of a Splunk server, Apache web server and Fortigate firewall virtual appliance Install and configure Splunk Enterprise and Splunk Universal Forwarder Know the different deployment types of Splunk Collect logs from remote nodes using Splunk Universal Forwarder Collect logs from Syslog devices like Fortigate firewall Search and explore data on Splunk Extract fields and add knowledge to data Quick introduction to Splunk Search Processing language (SPL) This course is ideal for individuals who are Security engineers or IT Administrators or Security operations center engineers or Security incident handlers or Systems administrators or Anyone wants to explore huge log files/feeds or Anyone interested to learn Splunk It is particularly useful for Security engineers or IT Administrators or Security operations center engineers or Security incident handlers or Systems administrators or Anyone wants to explore huge log files/feeds or Anyone interested to learn Splunk.

Enroll now: Splunk Basics Course

Summary

Title: Splunk Basics Course

Price: Free

Average Rating: 4.61

Number of Lectures: 20

Number of Published Lectures: 20

Number of Curriculum Items: 20

Number of Published Curriculum Objects: 20

Original Price: Free

Quality Status: approved

Status: Live

What You Will Learn

  • ICT Logging and monitoring basics
  • How to make logs work for you and get notified if something went wrong
  • Visualize data received from any log source in very simple steps
  • Build a small computer LAB that consists of a Splunk server, Apache web server and Fortigate firewall virtual appliance
  • Install and configure Splunk Enterprise and Splunk Universal Forwarder
  • Know the different deployment types of Splunk
  • Collect logs from remote nodes using Splunk Universal Forwarder
  • Collect logs from Syslog devices like Fortigate firewall
  • Search and explore data on Splunk
  • Extract fields and add knowledge to data
  • Quick introduction to Splunk Search Processing language (SPL)
  • Who Should Attend

  • Security engineers
  • IT Administrators
  • Security operations center engineers
  • Security incident handlers
  • Systems administrators
  • Anyone wants to explore huge log files/feeds
  • Anyone interested to learn Splunk
  • Target Audiences

  • Security engineers
  • IT Administrators
  • Security operations center engineers
  • Security incident handlers
  • Systems administrators
  • Anyone wants to explore huge log files/feeds
  • Anyone interested to learn Splunk
  • Machines are trying to tell us something through logs, so they are a very valuable resource for IT departments to ensure that everything is working as expected and to give us an idea of what is going on in our IT environments which will help to respond faster to incidents.

    In this hands-on course, we will learn how to set up a small virtual LAB to simulate real-world logging and monitoring scenarios, where we will collect logs from Apache web server and Fortigate firewall and send them to Splunk for storage, analysis, visualization and alerting.

    I selected these two log sources specifically because they represent the majority of log sources you will find in your environment, so you can follow the same steps in the course to integrate different log sources in the future.

    There are more complex log sources to integrate like logs that are pulled from database but they are not suitable to be discussed in an introductory course.

    After we onboard logs to Splunk, we will search and explore data we received then we will add knowledge to it by extracting interesting fields in these logs. 

    At this point, our logs will be ready to be treated by Splunk Searching Processing Language (SPL) to create reports, dashboards, and alerts.

    This course will make you ready to dig deep into more advanced topics of Splunk administration like,

  • High availability

  • Indexers clusters

  • Search head clusters

  • Deployments servers

  • Splunk Apps

  • Advanced SPL

  • But you have to walk before you run, so my vision for this course is to master the basics first to break the ice.

    Note:

    When the course was recorded Splunk version was 8.0.4.1, On 10-09-2022 I validated Splunk Enterprise 9.0.1on my own test lab and the steps and instructions in this course still apply.

    Course Curriculum

    Chapter 1: Introduction

    Lecture 1: Introduction to the course

    Lecture 2: Course structure

    Lecture 3: Udemy 101: Getting the most from this course

    Chapter 2: Preparing LAB

    Lecture 1: Installing VMware Workstation Player

    Lecture 2: Installing Ubuntu virtual machines

    Lecture 3: Assign Static IPs to Ubuntu machines and change default password

    Lecture 4: Downloading Splunk and installing Apache server

    Lecture 5: Importing Fortigate Appliance

    Chapter 3: Installing Splunk

    Lecture 1: Installing Splunk and Splunk Universal Forwarder

    Lecture 2: Deployment types

    Lecture 3: Configure Splunk to receive logs

    Chapter 4: Getting data in

    Lecture 1: Collecting logs from remote nodes

    Lecture 2: Configure Syslog source

    Chapter 5: Searching and exploring logs

    Lecture 1: Search and explore data on Splunk

    Lecture 2: Extract fields and add knowledge to data

    Lecture 3: Splunk Search Processing Language (SPL)

    Chapter 6: Reporting and monitoring

    Lecture 1: Creating reports and dashboards

    Lecture 2: Creating alerts

    Chapter 7: Keep learning

    Lecture 1: More to explore

    Lecture 2: Dont forget to leave a rating!

    Instructors

  • Splunk Basics Course  No.2
    Ahmed Elakwah
    Cybersecurity Consultant
  • Rating Distribution

  • 1 stars: 3 votes
  • 2 stars: 4 votes
  • 3 stars: 19 votes
  • 4 stars: 66 votes
  • 5 stars: 104 votes
  • Frequently Asked Questions

    How long do I have access to the course materials?

    You can view and review the lecture materials indefinitely, like an on-demand channel.

    Can I take my courses with me wherever I go?

    Definitely! If you have an internet connection, courses on Udemy are available on any device at any time. If you don’t have an internet connection, some instructors also let their students download course lectures. That’s up to the instructor though, so make sure you get on their good side!