{"course":{"productid":25908,"modality":1,"active":true,"language":"en","title":"Splunk Enterprise Cluster Administration","productcode":"SCLA","vendorcode":"SP","vendorname":"Splunk","fullproductcode":"SP-SCLA","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.ch\/course\/splunk-scla","essentials":"<p>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:<\/p>\n<ul>\n<li>Intro to Splunk<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-suf\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Using Fields <span class=\"fl-prod-pcode\">(SUF)<\/span><\/a><\/span><\/li><li>Introduction to Knowledge Objects<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cko\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Knowledge Objects <span class=\"fl-prod-pcode\">(CKO)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cfe\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Field Extractions <span class=\"fl-prod-pcode\">(CFE)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sesa\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise System Administration <span class=\"fl-prod-pcode\">(SESA)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-seda\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise Data Administration <span class=\"fl-prod-pcode\">(SEDA)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-tse\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Troubleshooting Splunk Enterprise <span class=\"fl-prod-pcode\">(TSE)<\/span><\/a><\/span><\/li><\/ul><p>Additional courses and\/or knowledge in these areas are also highly recommended:\n<\/p>\n<ul>\n<li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-edl\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Enriching Data with Lookups <span class=\"fl-prod-pcode\">(EDL)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sdm\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Data Models <span class=\"fl-prod-pcode\">(SDM)<\/span><\/a><\/span><\/li><\/ul>","audience":"<p>Splunk administrators.<\/p>","outline":"<p><strong>Module 1 &ndash; Overview of Large-scale Splunk Deployment<\/strong>\n<\/p>\n<ul>\n<li>Identify factors that affect large-scale deployment design<\/li><li>Describe approaches to scaling Splunk Enterprise<\/li><li>Configure Splunk License Manager<\/li><\/ul><p><strong>Module 2 &ndash; Deploying Single-site Indexer Clusters<\/strong>\n<\/p>\n<ul>\n<li>Identify indexer cluster states<\/li><li>Define replication factor and search factor<\/li><li>Implement a single-site indexer cluster<\/li><\/ul><p><strong>Module 3 &ndash; Deploying Multisite Indexer Clusters<\/strong>\n<\/p>\n<ul>\n<li>Define site replication factor and site search factor<\/li><li>Define search affinity<\/li><li>Implement a multisite indexer cluster<\/li><\/ul><p><strong>Module 4 &ndash; Updating Indexer Cluster Peer Configurations<\/strong>\n<\/p>\n<ul>\n<li>Distribute configurations and apps across peers<\/li><\/ul><p><strong>Module 5 - Managing and Monitoring Indexer Clusters<\/strong>\n<\/p>\n<ul>\n<li>Enable replication for clustered indexes<\/li><li>Configure Monitoring Console for indexer cluster environment<\/li><\/ul><p><strong>Module 6 &ndash; Configuring Indexer Discovery on Forwarders<\/strong>\n<\/p>\n<ul>\n<li>Configure indexer discovery<\/li><li>Configure indexer acknowledgment<\/li><li>Configure forwarder site failover<\/li><\/ul><p><strong>Module 7 &ndash; Deploying Search Head Cluster<\/strong>\n<\/p>\n<ul>\n<li>Configure a search head cluster<\/li><li>Connect clustered and non-clustered indexers<\/li><\/ul><p><strong>Module 8 &ndash; Managing and Monitoring Search Head Clusters<\/strong>\n<\/p>\n<ul>\n<li>Deploy configuration bundles to search head cluster members<\/li><li>Manage captaincy and member addition, removal and upgrades<\/li><\/ul><p><strong>Module 9 &ndash; Using KV Store in a Search Head Cluster<\/strong>\n<\/p>\n<ul>\n<li>Enable KV Store collection replication in a search head cluster<\/li><li>Monitor KV Store status with Monitoring Console<\/li><\/ul>","summary":"<p>The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment.<\/p>\n<p><strong>Please note that this class has 13.5 hours of content and may run over three days, with 4.5 hour sessions each day.<\/strong><\/p>","essentials_plain":"To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:\n\n\n- Intro to Splunk\n- Using Fields (SUF)\n- Introduction to Knowledge Objects\n- Creating Knowledge Objects (CKO)\n- Creating Field Extractions (CFE)\n- Splunk Enterprise System Administration (SESA)\n- Splunk Enterprise Data Administration (SEDA)\n- Troubleshooting Splunk Enterprise (TSE)\nAdditional courses and\/or knowledge in these areas are also highly recommended:\n\n\n\n- Enriching Data with Lookups (EDL)\n- Data Models (SDM)","audience_plain":"Splunk administrators.","outline_plain":"Module 1 \u2013 Overview of Large-scale Splunk Deployment\n\n\n\n- Identify factors that affect large-scale deployment design\n- Describe approaches to scaling Splunk Enterprise\n- Configure Splunk License Manager\nModule 2 \u2013 Deploying Single-site Indexer Clusters\n\n\n\n- Identify indexer cluster states\n- Define replication factor and search factor\n- Implement a single-site indexer cluster\nModule 3 \u2013 Deploying Multisite Indexer Clusters\n\n\n\n- Define site replication factor and site search factor\n- Define search affinity\n- Implement a multisite indexer cluster\nModule 4 \u2013 Updating Indexer Cluster Peer Configurations\n\n\n\n- Distribute configurations and apps across peers\nModule 5 - Managing and Monitoring Indexer Clusters\n\n\n\n- Enable replication for clustered indexes\n- Configure Monitoring Console for indexer cluster environment\nModule 6 \u2013 Configuring Indexer Discovery on Forwarders\n\n\n\n- Configure indexer discovery\n- Configure indexer acknowledgment\n- Configure forwarder site failover\nModule 7 \u2013 Deploying Search Head Cluster\n\n\n\n- Configure a search head cluster\n- Connect clustered and non-clustered indexers\nModule 8 \u2013 Managing and Monitoring Search Head Clusters\n\n\n\n- Deploy configuration bundles to search head cluster members\n- Manage captaincy and member addition, removal and upgrades\nModule 9 \u2013 Using KV Store in a Search Head Cluster\n\n\n\n- Enable KV Store collection replication in a search head cluster\n- Monitor KV Store status with Monitoring Console","summary_plain":"The course provides the fundamental knowledge of deploying and managing Splunk Enterprise in a clustered environment.\n\nPlease note that this class has 13.5 hours of content and may run over three days, with 4.5 hour sessions each day.","skill_level":"Intermediate","version":"9.3","duration":{"unit":"d","value":2,"formatted":"2 days"},"pricelist":{"List Price":{"US":{"country":"US","currency":"USD","taxrate":null,"price":1500},"GB":{"country":"GB","currency":"GBP","taxrate":20,"price":1250},"PL":{"country":"PL","currency":"USD","taxrate":23,"price":1500},"DE":{"country":"DE","currency":"EUR","taxrate":19,"price":1500},"AT":{"country":"AT","currency":"EUR","taxrate":20,"price":1500},"SE":{"country":"SE","currency":"EUR","taxrate":25,"price":1500},"CA":{"country":"CA","currency":"CAD","taxrate":null,"price":2070},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":1650},"NL":{"country":"NL","currency":"EUR","taxrate":21,"price":1500}}},"lastchanged":"2026-01-21T18:41:10+01:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/en\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course-schedule\/25908","source_lang":"en","source":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course\/splunk-scla"}}