{"course":{"productid":25903,"modality":1,"active":true,"language":"en","title":"Troubleshooting Splunk Enterprise","productcode":"TSE","vendorcode":"SP","vendorname":"Splunk","fullproductcode":"SP-TSE","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.ch\/course\/splunk-tse","essentials":"<p>To be successful, students must have completed these Splunk Education course(s) or have equivalent working experience:<\/p>\n<ul>\n<li>Intro to Splunk<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-suf\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Using Fields <span class=\"fl-prod-pcode\">(SUF)<\/span><\/a><\/span><\/li><li>Introduction to Knowledge Objects<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cko\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Knowledge Objects <span class=\"fl-prod-pcode\">(CKO)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-cfe\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Creating Field Extractions <span class=\"fl-prod-pcode\">(CFE)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sesa\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise System Administration <span class=\"fl-prod-pcode\">(SESA)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-seda\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Splunk Enterprise Data Administration <span class=\"fl-prod-pcode\">(SEDA)<\/span><\/a><\/span><\/li><\/ul><p>Additional courses and\/or knowledge in these areas are also highly recommended:<\/p>\n<ul>\n<li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-edl\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Enriching Data with Lookups <span class=\"fl-prod-pcode\">(EDL)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/en\/course\/splunk-sdm\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Data Models <span class=\"fl-prod-pcode\">(SDM)<\/span><\/a><\/span><\/li><\/ul>","audience":"<p>Administrators<\/p>","outline":"<p><strong>Module 1 &ndash; Splunk Troubleshooting Methods and Tools<\/strong><\/p>\n<ul>\n<li>Describe the Splunk Troubleshooting Approach<\/li><li>List Splunk Diagnostic Resources and Tools<\/li><li>Create and Splunk a Diag<\/li><li>Use RapidDiag<\/li><\/ul><p><strong>Module 2 &ndash; Indexing Problems<\/strong><\/p>\n<ul>\n<li>Discover Splunk Deployment Topology and its Server Roles<\/li><li>Identify Where to Check the Index-Time Pipeline Status<\/li><li>Use the metrics.log to Clarify the Index-Time Problem<\/li><\/ul><p><strong>Module 3 &ndash; Input Configuration Problems<\/strong><\/p>\n<ul>\n<li>Data Input Issues<\/li><li>Troubleshooting Inputs with the Monitoring Console<\/li><\/ul><p><strong>Module 4 &ndash; Deployment and Forwarder Problems<\/strong>\n<\/p>\n<ul>\n<li>Deployment Server Issues<\/li><li>Forwarding and Receiving Issues<\/li><\/ul><p><strong>Module 5 &ndash; Search Management Problems<\/strong>\n<\/p>\n<ul>\n<li>Troubleshoot Distributed Search Issues<\/li><li>Identify Job Scheduling Problems<\/li><li>Learn to Diagnose Crashing Problems<\/li><li>Describe How to Prioritize Resources for Critical Splunk Processes<\/li><\/ul><p><strong>Module 6 &ndash; User Search Problems<\/strong>\n<\/p>\n<ul>\n<li>Identify the Types of Search Problems<\/li><li>Isolate and Troubleshoot Search Problems<\/li><\/ul>","summary":"<p>The course covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available with Splunk Enterprise.<\/p>\n<p><strong>This course may be delivered in one day or, two days of 4.5 hour sessions.<\/strong><\/p>","essentials_plain":"To be successful, students must have completed these Splunk Education course(s) or have equivalent working experience:\n\n\n- Intro to Splunk\n- Using Fields (SUF)\n- Introduction to Knowledge Objects\n- Creating Knowledge Objects (CKO)\n- Creating Field Extractions (CFE)\n- Splunk Enterprise System Administration (SESA)\n- Splunk Enterprise Data Administration (SEDA)\nAdditional courses and\/or knowledge in these areas are also highly recommended:\n\n\n- Enriching Data with Lookups (EDL)\n- Data Models (SDM)","audience_plain":"Administrators","outline_plain":"Module 1 \u2013 Splunk Troubleshooting Methods and Tools\n\n\n- Describe the Splunk Troubleshooting Approach\n- List Splunk Diagnostic Resources and Tools\n- Create and Splunk a Diag\n- Use RapidDiag\nModule 2 \u2013 Indexing Problems\n\n\n- Discover Splunk Deployment Topology and its Server Roles\n- Identify Where to Check the Index-Time Pipeline Status\n- Use the metrics.log to Clarify the Index-Time Problem\nModule 3 \u2013 Input Configuration Problems\n\n\n- Data Input Issues\n- Troubleshooting Inputs with the Monitoring Console\nModule 4 \u2013 Deployment and Forwarder Problems\n\n\n\n- Deployment Server Issues\n- Forwarding and Receiving Issues\nModule 5 \u2013 Search Management Problems\n\n\n\n- Troubleshoot Distributed Search Issues\n- Identify Job Scheduling Problems\n- Learn to Diagnose Crashing Problems\n- Describe How to Prioritize Resources for Critical Splunk Processes\nModule 6 \u2013 User Search Problems\n\n\n\n- Identify the Types of Search Problems\n- Isolate and Troubleshoot Search Problems","summary_plain":"The course covers topics and techniques for troubleshooting a standard Splunk distributed deployment using the tools available with Splunk Enterprise.\n\nThis course may be delivered in one day or, two days of 4.5 hour sessions.","skill_level":"Intermediate","version":"9.4","duration":{"unit":"d","value":1,"formatted":"1 day"},"pricelist":{"List Price":{"US":{"country":"US","currency":"USD","taxrate":null,"price":1000},"GB":{"country":"GB","currency":"GBP","taxrate":20,"price":835},"PL":{"country":"PL","currency":"USD","taxrate":23,"price":1000},"DE":{"country":"DE","currency":"EUR","taxrate":19,"price":1000},"AT":{"country":"AT","currency":"EUR","taxrate":20,"price":1000},"SE":{"country":"SE","currency":"EUR","taxrate":25,"price":1000},"CA":{"country":"CA","currency":"CAD","taxrate":null,"price":1380},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":1100},"NL":{"country":"NL","currency":"EUR","taxrate":21,"price":1000}}},"lastchanged":"2026-01-13T17:43:08+01:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/en\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course-schedule\/25903","source_lang":"en","source":"https:\/\/portal.flane.ch\/swisscom\/en\/json-course\/splunk-tse"}}