{"course":{"productid":25904,"modality":1,"active":true,"language":"en","title":"Transitioning to Splunk Cloud","productcode":"TSC","vendorcode":"SP","vendorname":"Splunk","fullproductcode":"SP-TSC","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.ch\/course\/splunk-tsc","essentials":"<p>To be successful, students must have completed these Splunk Education course(s) or have equivalent working\nknowledge:<\/p>\n<ul>\n<li>Intro to Splunk<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-suf\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Using Fields <span class=\"fl-prod-pcode\">(SUF)<\/span><\/a><\/span><\/li><li>Intro to Knowledge Objects<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cko\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Knowledge Objects <span class=\"fl-prod-pcode\">(CKO)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cfe\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Field Extractions <span class=\"fl-prod-pcode\">(CFE)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sesa\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise System Administration <span class=\"fl-prod-pcode\">(SESA)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-seda\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise Data Administration <span class=\"fl-prod-pcode\">(SEDA)<\/span><\/a><\/span><\/li><\/ul><p>Additional courses and\/or knowledge in these areas are also highly recommended:\n<\/p>\n<ul>\n<li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-edl\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Enriching Data with Lookups <span class=\"fl-prod-pcode\">(EDL)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sdm\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Data Models <span class=\"fl-prod-pcode\">(SDM)<\/span><\/a><\/span><\/li><\/ul>","audience":"<p>Splunk Enterprise Administrators<\/p>","contents":"<p>This course is for experienced on-prem administrators and anyone needing to ramp-up on Splunk Cloud to get more knowledge and experience of managing Splunk Cloud instances.<\/p>\n<p>The course discusses the differentiators between on-prem Splunk and the different Splunk Cloud offerings. Modules include topics on how to migrate data collection and ingest from on-prem Splunk to Splunk Cloud as well as highlighting Splunk Cloud specific differences and best practices to manage a productive Splunk SaaS deployment. For Splunk Administrators who have undertaken the System and Data Administration learning pathways, this course highlights key differences between Splunk Enterprise deployed on-premises and Splunk Enterprise Cloud to allow them to ramp up their data and system management skills to transition to Splunk Cloud. The hands-on lab provides access to and experience of managing a Splunk Cloud instance.<\/p>\n<p>Note: Splunk Cloud Administration and Transitioning to Splunk Cloud SHOULD NOT be taken together as both are designed to develop Splunk Cloud-specific skills and as such there is some overlap.<\/p>\n<p> <strong>Please note that this course may run over two days, with 4.5 hour sessions each day.<\/strong><\/p>","outline":"<p><strong>Module 1 &ndash; Splunk Cloud Overview<\/strong>\n<\/p>\n<ul>\n<li>Describe Splunk and Splunk Cloud features and topology<\/li><li>Identify Splunk Cloud administrator tasks<\/li><li>Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience<\/li><li>Secure Splunk deployments best practices<\/li><li>Explain Splunk Cloud data ingestion strategies<\/li><\/ul><p><strong>Module 2 &ndash; Splunk Cloud Migration<\/strong>\n<\/p>\n<ul>\n<li>Understand the Splunk Cloud migration journey<\/li><li>Determine Splunk Cloud migration readiness<\/li><li>Identify Splunk Cloud migration preparation tasks, strategies, and possible challenges<\/li><\/ul><p><strong>Module 3 &ndash; Managing Users<\/strong>\n<\/p>\n<ul>\n<li>Identify Splunk Cloud authentication options<\/li><li>Add Splunk users using native authentication<\/li><li>Create a custom role<\/li><li>Integrate Splunk with LDAP, Active Directory or SAML<\/li><li>Use Workload Management to manage user resource usage<\/li><li>Manage users in Splunk<\/li><\/ul><p><strong>Module 4 &ndash; Managing Indexes<\/strong>\n<\/p>\n<ul>\n<li>Understand cloud indexing strategy<\/li><li>Define and create indexes<\/li><li>Manage data retention and archiving<\/li><li>Delete and mask data from an index<\/li><li>Monitor indexing activities<\/li><\/ul><p><strong>Module 5 &ndash; Managing Apps<\/strong>\n<\/p>\n<ul>\n<li>Review the process for installing apps<\/li><li>Define the purpose of private apps<\/li><li>Upload private apps<\/li><li>Describe how apps are managed<\/li><\/ul><p><strong>Module 6 &ndash; Configuring Forwarders<\/strong>\n<\/p>\n<ul>\n<li>List Splunk forwarder types<\/li><li>Understand the role of forwarders<\/li><li>Configure a forwarder to send data to Splunk Cloud<\/li><li>Test the forwarder connection<\/li><li>Describe optional forwarder settings<\/li><\/ul><p><strong>Module 7 &ndash; Common Inputs<\/strong>\n<\/p>\n<ul>\n<li>Describe forwarder inputs such as files and directories<\/li><li>Create REST API inputs<\/li><li>Create a basic scripted input<\/li><li>Create Splunk HTTP Event Collector (HEC) agentless inputs<\/li><\/ul><p><strong>Module 8 &ndash; Additional Inputs<\/strong>\n<\/p>\n<ul>\n<li>Understand how inputs are managed using apps or add-ons<\/li><li>Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub<\/li><\/ul><p><strong>Module 9 &ndash; Using Ingest Actions<\/strong>\n<\/p>\n<ul>\n<li>Explore Splunk transformation methods<\/li><li>Create and manage rulesets with Ingest Actions<\/li><li>Mask, filter and route data with Ingest Action rules<\/li><\/ul><p><strong>Module 10 &ndash; Managing Splunk Cloud<\/strong>\n<\/p>\n<ul>\n<li>Secure ingest with Splunk Cloud Private Connectivity with AWS<\/li><li>Describe Federated Search functionality<\/li><li>Describe Splunk connected experience apps such as Splunk Secure Gateway<\/li><li>Monitor and manage resource utilization by business units and users using Splunk App for Chargeback<\/li><li>Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service<\/li><\/ul><p><strong>Module 11 &ndash; Supporting Splunk Cloud<\/strong>\n<\/p>\n<ul>\n<li>Know how to isolate problems before contacting Splunk Cloud Support<\/li><li>Use Isolation Troubleshooting<\/li><li>Define the process for engaging Splunk Support<\/li><\/ul><p><strong>Appendix<\/strong>\n<\/p>\n<ul>\n<li>Explore Splunk security fundamentals<\/li><\/ul>","essentials_plain":"To be successful, students must have completed these Splunk Education course(s) or have equivalent working\nknowledge:\n\n\n- Intro to Splunk\n- Using Fields (SUF)\n- Intro to Knowledge Objects\n- Creating Knowledge Objects (CKO)\n- Creating Field Extractions (CFE)\n- Splunk Enterprise System Administration (SESA)\n- Splunk Enterprise Data Administration (SEDA)\nAdditional courses and\/or knowledge in these areas are also highly recommended:\n\n\n\n- Enriching Data with Lookups (EDL)\n- Data Models (SDM)","audience_plain":"Splunk Enterprise Administrators","contents_plain":"This course is for experienced on-prem administrators and anyone needing to ramp-up on Splunk Cloud to get more knowledge and experience of managing Splunk Cloud instances.\n\nThe course discusses the differentiators between on-prem Splunk and the different Splunk Cloud offerings. Modules include topics on how to migrate data collection and ingest from on-prem Splunk to Splunk Cloud as well as highlighting Splunk Cloud specific differences and best practices to manage a productive Splunk SaaS deployment. For Splunk Administrators who have undertaken the System and Data Administration learning pathways, this course highlights key differences between Splunk Enterprise deployed on-premises and Splunk Enterprise Cloud to allow them to ramp up their data and system management skills to transition to Splunk Cloud. The hands-on lab provides access to and experience of managing a Splunk Cloud instance.\n\nNote: Splunk Cloud Administration and Transitioning to Splunk Cloud SHOULD NOT be taken together as both are designed to develop Splunk Cloud-specific skills and as such there is some overlap.\n\n Please note that this course may run over two days, with 4.5 hour sessions each day.","outline_plain":"Module 1 \u2013 Splunk Cloud Overview\n\n\n\n- Describe Splunk and Splunk Cloud features and topology\n- Identify Splunk Cloud administrator tasks\n- Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience\n- Secure Splunk deployments best practices\n- Explain Splunk Cloud data ingestion strategies\nModule 2 \u2013 Splunk Cloud Migration\n\n\n\n- Understand the Splunk Cloud migration journey\n- Determine Splunk Cloud migration readiness\n- Identify Splunk Cloud migration preparation tasks, strategies, and possible challenges\nModule 3 \u2013 Managing Users\n\n\n\n- Identify Splunk Cloud authentication options\n- Add Splunk users using native authentication\n- Create a custom role\n- Integrate Splunk with LDAP, Active Directory or SAML\n- Use Workload Management to manage user resource usage\n- Manage users in Splunk\nModule 4 \u2013 Managing Indexes\n\n\n\n- Understand cloud indexing strategy\n- Define and create indexes\n- Manage data retention and archiving\n- Delete and mask data from an index\n- Monitor indexing activities\nModule 5 \u2013 Managing Apps\n\n\n\n- Review the process for installing apps\n- Define the purpose of private apps\n- Upload private apps\n- Describe how apps are managed\nModule 6 \u2013 Configuring Forwarders\n\n\n\n- List Splunk forwarder types\n- Understand the role of forwarders\n- Configure a forwarder to send data to Splunk Cloud\n- Test the forwarder connection\n- Describe optional forwarder settings\nModule 7 \u2013 Common Inputs\n\n\n\n- Describe forwarder inputs such as files and directories\n- Create REST API inputs\n- Create a basic scripted input\n- Create Splunk HTTP Event Collector (HEC) agentless inputs\nModule 8 \u2013 Additional Inputs\n\n\n\n- Understand how inputs are managed using apps or add-ons\n- Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub\nModule 9 \u2013 Using Ingest Actions\n\n\n\n- Explore Splunk transformation methods\n- Create and manage rulesets with Ingest Actions\n- Mask, filter and route data with Ingest Action rules\nModule 10 \u2013 Managing Splunk Cloud\n\n\n\n- Secure ingest with Splunk Cloud Private Connectivity with AWS\n- Describe Federated Search functionality\n- Describe Splunk connected experience apps such as Splunk Secure Gateway\n- Monitor and manage resource utilization by business units and users using Splunk App for Chargeback\n- Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service\nModule 11 \u2013 Supporting Splunk Cloud\n\n\n\n- Know how to isolate problems before contacting Splunk Cloud Support\n- Use Isolation Troubleshooting\n- Define the process for engaging Splunk Support\nAppendix\n\n\n\n- Explore Splunk security fundamentals","skill_level":"Beginner","version":"9.4","duration":{"unit":"d","value":0,"formatted":"9 hours"},"pricelist":{"List Price":{"US":{"country":"US","currency":"USD","taxrate":null,"price":1000},"GB":{"country":"GB","currency":"GBP","taxrate":20,"price":835},"PL":{"country":"PL","currency":"USD","taxrate":23,"price":1000},"DE":{"country":"DE","currency":"EUR","taxrate":19,"price":1000},"CA":{"country":"CA","currency":"CAD","taxrate":null,"price":1380},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":1100},"NL":{"country":"NL","currency":"EUR","taxrate":21,"price":1000}}},"lastchanged":"2025-11-26T11:44:38+01:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/en\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course-schedule\/25904","source_lang":"en","source":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course\/splunk-tsc"}}