<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="29605" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-power-u" lastchanged="2026-02-16T21:24:52+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Splunk Power User Fast Start</title><productcode>POWER-U</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-POWER-U</fullproductcode><version>10</version><objective>&lt;ul&gt;
&lt;li&gt;Utilize over 60 commands and functions to transform, manipulate, normalize, correlate, and filter data.&lt;/li&gt;&lt;li&gt;Filter data using time modifiers and time commands and use formatting functions to accommodate various time formats.&lt;/li&gt;&lt;li&gt;Calculate statistics using transforming commands and mathematical and statistical eval functions.&lt;/li&gt;&lt;li&gt;Compare, manipulate, and normalize data using several commands including the all-powerful eval command and an array of statistical, comparison, conditional, and formatting functions.&lt;/li&gt;&lt;li&gt;Calculate co-occurrence between fields and analyze data from multiple datasets.&lt;/li&gt;&lt;li&gt;Create, curate, manage and share knowledge objects.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful, students should have a solid understanding of the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk works&lt;/li&gt;&lt;li&gt;How to create basic searching and visualizations&lt;/li&gt;&lt;/ul&gt;</essentials><contents>&lt;ul&gt;
&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-wwt&quot;&gt;Working with Time &lt;span class=&quot;fl-prod-pcode&quot;&gt;(WWT)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-ssp&quot;&gt;Statistical Processing &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SSP)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-scv&quot;&gt;Comparing Values &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCV)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-srm&quot;&gt;Result Modification &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SRM)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sclas&quot;&gt;Correlation Analysis &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCLAS)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Topic 1 &amp;ndash; Working with Time&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Formatting Time&lt;/li&gt;&lt;li&gt;Comparing Index Time versus Search Time&lt;/li&gt;&lt;li&gt;Using Time Commands&lt;/li&gt;&lt;li&gt;Working with Time Zones&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 2 &amp;ndash; Statistical Processing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What is a Data Series?&lt;/li&gt;&lt;li&gt;Transforming Data&lt;/li&gt;&lt;li&gt;Manipulating Data with eval&lt;/li&gt;&lt;li&gt;Formatting Data&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 3 &amp;ndash; Comparing Values&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using eval to Compare&lt;/li&gt;&lt;li&gt;Filtering with where&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 4 &amp;ndash; Result Modification&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Manipulating Output&lt;/li&gt;&lt;li&gt;Modifying Results Sets&lt;/li&gt;&lt;li&gt;Managing Missing Data&lt;/li&gt;&lt;li&gt;Modifying Field Values&lt;/li&gt;&lt;li&gt;Normalizing with eval&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 5 &amp;ndash; Correlation Analysis&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Calculate Co-Occurrence Between Fields&lt;/li&gt;&lt;li&gt;Analyze Multiple Datasets&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 6 &amp;ndash; Intro to Knowledge Objects&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What are Knowledge Objects?&lt;/li&gt;&lt;li&gt;Knowledge Object Settings&lt;/li&gt;&lt;li&gt;Managing Knowledge Objects&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 7 &amp;ndash; Creating Knowledge Objects&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Knowledge Objects and Search-time Operations&lt;/li&gt;&lt;li&gt;Creating Event Types&lt;/li&gt;&lt;li&gt;Using Event Type Builder&lt;/li&gt;&lt;li&gt;Creating Workflow Actions&lt;/li&gt;&lt;li&gt;Creating Tags and Aliases&lt;/li&gt;&lt;li&gt;Creating Search Macros&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 8 &amp;ndash; Creating Field Extractions&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using the Field Extractor&lt;/li&gt;&lt;li&gt;Creating Regex Field Extractions&lt;/li&gt;&lt;li&gt;Creating Delimited Field Extractions&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 9 &amp;ndash; Data Models&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Introducing Data Model Datasets&lt;/li&gt;&lt;li&gt;Designing Data Models&lt;/li&gt;&lt;li&gt;Creating a Pivot&lt;/li&gt;&lt;li&gt;Accelerating Data Models&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>- Utilize over 60 commands and functions to transform, manipulate, normalize, correlate, and filter data.
- Filter data using time modifiers and time commands and use formatting functions to accommodate various time formats.
- Calculate statistics using transforming commands and mathematical and statistical eval functions.
- Compare, manipulate, and normalize data using several commands including the all-powerful eval command and an array of statistical, comparison, conditional, and formatting functions.
- Calculate co-occurrence between fields and analyze data from multiple datasets.
- Create, curate, manage and share knowledge objects.</objective_plain><essentials_plain>To be successful, students should have a solid understanding of the following:


- How Splunk works
- How to create basic searching and visualizations</essentials_plain><contents_plain>- Working with Time (WWT)
- Statistical Processing (SSP)
- Comparing Values (SCV)
- Result Modification (SRM)
- Correlation Analysis (SCLAS)
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Data Models (SDM)</contents_plain><outline_plain>Topic 1 – Working with Time


- Formatting Time
- Comparing Index Time versus Search Time
- Using Time Commands
- Working with Time Zones
Topic 2 – Statistical Processing


- What is a Data Series?
- Transforming Data
- Manipulating Data with eval
- Formatting Data
Topic 3 – Comparing Values


- Using eval to Compare
- Filtering with where
Topic 4 – Result Modification


- Manipulating Output
- Modifying Results Sets
- Managing Missing Data
- Modifying Field Values
- Normalizing with eval
Topic 5 – Correlation Analysis


- Calculate Co-Occurrence Between Fields
- Analyze Multiple Datasets
Topic 6 – Intro to Knowledge Objects


- What are Knowledge Objects?
- Knowledge Object Settings
- Managing Knowledge Objects
Topic 7 – Creating Knowledge Objects


- Knowledge Objects and Search-time Operations
- Creating Event Types
- Using Event Type Builder
- Creating Workflow Actions
- Creating Tags and Aliases
- Creating Search Macros
Topic 8 – Creating Field Extractions


- Using the Field Extractor
- Creating Regex Field Extractions
- Creating Delimited Field Extractions
Topic 9 – Data Models


- Introducing Data Model Datasets
- Designing Data Models
- Creating a Pivot
- Accelerating Data Models</outline_plain><duration unit="d" days="4">4 days</duration><pricelist><price country="SI" currency="EUR">4000.00</price><price country="GR" currency="EUR">4000.00</price><price country="MK" currency="EUR">4000.00</price><price country="HU" currency="EUR">4000.00</price><price country="GB" currency="GBP">3335.00</price><price country="FR" currency="EUR">4000.00</price><price country="PL" currency="USD">4000.00</price><price country="DE" currency="EUR">4000.00</price><price country="IT" currency="USD">4000.00</price><price country="NL" currency="EUR">4000.00</price><price country="UA" currency="USD">4000.00</price><price country="CH" currency="CHF">4400.00</price><price country="AT" currency="EUR">4000.00</price></pricelist><miles><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="FR" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue></miles></course>