<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="25907" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-sca" lastchanged="2026-01-12T11:20:09+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Splunk Cloud Administration</title><productcode>SCA</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SCA</fullproductcode><version>9.4</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Intro to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Additional courses and/or knowledge in these areas are also highly recommended:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Splunk Cloud Administrators.&lt;/p&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; Splunk Cloud Overview&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Splunk and Splunk Cloud features and topology&lt;/li&gt;&lt;li&gt;Identify Splunk Cloud administrator tasks&lt;/li&gt;&lt;li&gt;Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience&lt;/li&gt;&lt;li&gt;Secure Splunk deployments best practices&lt;/li&gt;&lt;li&gt;Explain Splunk Cloud data ingestion strategies&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 - Managing Users&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Splunk Cloud authentication options&lt;/li&gt;&lt;li&gt;Add Splunk users using native authentication&lt;/li&gt;&lt;li&gt;Create a custom role&lt;/li&gt;&lt;li&gt;Integrate Splunk with LDAP, Active Directory or SAML&lt;/li&gt;&lt;li&gt;Use Workload Management to manage user resource usage&lt;/li&gt;&lt;li&gt;Manage users in Splunk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Managing Indexes&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand cloud indexing strategy&lt;/li&gt;&lt;li&gt;Define and create indexes&lt;/li&gt;&lt;li&gt;Manage data retention and archiving&lt;/li&gt;&lt;li&gt;Delete and mask data from an index&lt;/li&gt;&lt;li&gt;Monitor indexing activities&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Using Configuration Files&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Splunk configuration directory structure&lt;/li&gt;&lt;li&gt;Describe the configuration layering process with index and search time precedence&lt;/li&gt;&lt;li&gt;Use Splunk tools to examine configuration settings such as btool&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Managing Apps&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review the process for installing apps&lt;/li&gt;&lt;li&gt;Define the purpose of private apps&lt;/li&gt;&lt;li&gt;Upload private apps&lt;/li&gt;&lt;li&gt;Describe how apps are managed&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Configuring Forwarders&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List Splunk forwarder types&lt;/li&gt;&lt;li&gt;Understand the role of forwarders&lt;/li&gt;&lt;li&gt;Configure a forwarder to send data to Splunk Cloud&lt;/li&gt;&lt;li&gt;Test the forwarder connection&lt;/li&gt;&lt;li&gt;Describe optional forwarder settings&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Managing Forwarders&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Splunk Deployment Server (DS)&lt;/li&gt;&lt;li&gt;Manage forwarders using deployment apps&lt;/li&gt;&lt;li&gt;Configure deployment clients and client groups&lt;/li&gt;&lt;li&gt;Monitor forwarder management activities&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; Forwarder Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Splunk process for inputting data&lt;/li&gt;&lt;li&gt;Create file and directory monitor inputs&lt;/li&gt;&lt;li&gt;Use optional settings for monitor inputs&lt;/li&gt;&lt;li&gt;Creating network inputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Common Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create REST API inputs&lt;/li&gt;&lt;li&gt;Create a basic scripted input&lt;/li&gt;&lt;li&gt;Identify Linux-specific inputs&lt;/li&gt;&lt;li&gt;Identify Windows-specific inputs&lt;/li&gt;&lt;li&gt;Create Splunk HTTP Event Collector (HEC) agentless inputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10 &amp;ndash; Additional Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand how inputs are managed using apps or add-ons&lt;/li&gt;&lt;li&gt;Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 11 &amp;ndash; Fine-tuning Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the default processing that occurs during the input phase&lt;/li&gt;&lt;li&gt;Configure input phase options, such as source type fine-tuning and character set encoding&lt;/li&gt;&lt;li&gt;Reset file check pointers on a forwarder using the btprobe command&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 12 &amp;ndash; Parsing Phase and Data Preview&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the default processing that occurs during parsing&lt;/li&gt;&lt;li&gt;Optimize and configure event line breaking&lt;/li&gt;&lt;li&gt;Modify how timestamps and time zones are extracted or assigned to events&lt;/li&gt;&lt;li&gt;Use Data Preview to validate event creation during the parsing phase&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 13 &amp;ndash; Manipulating Input Data&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explore Splunk transformation methods&lt;/li&gt;&lt;li&gt;Mask, filter and route data with SEDCMD and TRANSFORMS&lt;/li&gt;&lt;li&gt;Override sourcetype or host based upon event values&lt;/li&gt;&lt;li&gt;Create and manage rulesets with Ingest Actions&lt;/li&gt;&lt;li&gt;Mask, filter and route data with Ingest Action rules&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 14 &amp;ndash; Managing Splunk Cloud&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Secure ingest with Splunk Cloud Private Connectivity with AWS&lt;/li&gt;&lt;li&gt;Describe Federated Search functionality&lt;/li&gt;&lt;li&gt;Describe Splunk connected experience apps such as Splunk Secure Gateway&lt;/li&gt;&lt;li&gt;Monitor and manage resource utilization by business units and users using Splunk App for Chargeback&lt;/li&gt;&lt;li&gt;Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 15 &amp;ndash; Supporting Splunk Cloud&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Know how to isolate problems before contacting Splunk Cloud Support&lt;/li&gt;&lt;li&gt;Use Isolation Troubleshooting&lt;/li&gt;&lt;li&gt;Define the process for engaging Splunk Support&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Appendix&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explore Splunk security fundamentals&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:


- Intro to Splunk
- Using Fields (SUF)
- Intro to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
Additional courses and/or knowledge in these areas are also highly recommended:



- Enriching Data with Lookups (EDL)
- Data Models (SDM)</essentials_plain><audience_plain>Splunk Cloud Administrators.</audience_plain><outline_plain>Module 1 – Splunk Cloud Overview


- Describe Splunk and Splunk Cloud features and topology
- Identify Splunk Cloud administrator tasks
- Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience
- Secure Splunk deployments best practices
- Explain Splunk Cloud data ingestion strategies
Module 2 - Managing Users



- Identify Splunk Cloud authentication options
- Add Splunk users using native authentication
- Create a custom role
- Integrate Splunk with LDAP, Active Directory or SAML
- Use Workload Management to manage user resource usage
- Manage users in Splunk
Module 3 – Managing Indexes



- Understand cloud indexing strategy
- Define and create indexes
- Manage data retention and archiving
- Delete and mask data from an index
- Monitor indexing activities
Module 4 – Using Configuration Files



- Describe Splunk configuration directory structure
- Describe the configuration layering process with index and search time precedence
- Use Splunk tools to examine configuration settings such as btool
Module 5 – Managing Apps



- Review the process for installing apps
- Define the purpose of private apps
- Upload private apps
- Describe how apps are managed
Module 6 – Configuring Forwarders



- List Splunk forwarder types
- Understand the role of forwarders
- Configure a forwarder to send data to Splunk Cloud
- Test the forwarder connection
- Describe optional forwarder settings
Module 7 – Managing Forwarders



- Describe Splunk Deployment Server (DS)
- Manage forwarders using deployment apps
- Configure deployment clients and client groups
- Monitor forwarder management activities
Module 8 – Forwarder Inputs



- Describe the Splunk process for inputting data
- Create file and directory monitor inputs
- Use optional settings for monitor inputs
- Creating network inputs
Module 9 – Common Inputs



- Create REST API inputs
- Create a basic scripted input
- Identify Linux-specific inputs
- Identify Windows-specific inputs
- Create Splunk HTTP Event Collector (HEC) agentless inputs
Module 10 – Additional Inputs



- Understand how inputs are managed using apps or add-ons
- Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub
Module 11 – Fine-tuning Inputs



- Describe the default processing that occurs during the input phase
- Configure input phase options, such as source type fine-tuning and character set encoding
- Reset file check pointers on a forwarder using the btprobe command
Module 12 – Parsing Phase and Data Preview



- Describe the default processing that occurs during parsing
- Optimize and configure event line breaking
- Modify how timestamps and time zones are extracted or assigned to events
- Use Data Preview to validate event creation during the parsing phase
Module 13 – Manipulating Input Data



- Explore Splunk transformation methods
- Mask, filter and route data with SEDCMD and TRANSFORMS
- Override sourcetype or host based upon event values
- Create and manage rulesets with Ingest Actions
- Mask, filter and route data with Ingest Action rules
Module 14 – Managing Splunk Cloud



- Secure ingest with Splunk Cloud Private Connectivity with AWS
- Describe Federated Search functionality
- Describe Splunk connected experience apps such as Splunk Secure Gateway
- Monitor and manage resource utilization by business units and users using Splunk App for Chargeback
- Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service
Module 15 – Supporting Splunk Cloud



- Know how to isolate problems before contacting Splunk Cloud Support
- Use Isolation Troubleshooting
- Define the process for engaging Splunk Support
Appendix



- Explore Splunk security fundamentals</outline_plain><duration unit="d" days="2">2.5 days</duration><pricelist><price country="US" currency="USD">2000.00</price><price country="GB" currency="GBP">1670.00</price><price country="PL" currency="USD">2000.00</price><price country="DE" currency="EUR">2250.00</price><price country="AT" currency="EUR">2250.00</price><price country="SE" currency="EUR">2250.00</price><price country="CA" currency="CAD">2760.00</price><price country="FR" currency="EUR">2000.00</price><price country="CH" currency="CHF">2500.00</price><price country="NL" currency="EUR">2250.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">200.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue></miles></course>