<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="25908" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-scla" lastchanged="2026-01-21T18:41:10+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Splunk Enterprise Cluster Administration</title><productcode>SCLA</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SCLA</fullproductcode><version>9.3</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Introduction to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-seda&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Data Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEDA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-tse&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Troubleshooting Splunk Enterprise &lt;span class=&quot;fl-prod-pcode&quot;&gt;(TSE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Additional courses and/or knowledge in these areas are also highly recommended:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Splunk administrators.&lt;/p&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; Overview of Large-scale Splunk Deployment&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify factors that affect large-scale deployment design&lt;/li&gt;&lt;li&gt;Describe approaches to scaling Splunk Enterprise&lt;/li&gt;&lt;li&gt;Configure Splunk License Manager&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Deploying Single-site Indexer Clusters&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify indexer cluster states&lt;/li&gt;&lt;li&gt;Define replication factor and search factor&lt;/li&gt;&lt;li&gt;Implement a single-site indexer cluster&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Deploying Multisite Indexer Clusters&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define site replication factor and site search factor&lt;/li&gt;&lt;li&gt;Define search affinity&lt;/li&gt;&lt;li&gt;Implement a multisite indexer cluster&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Updating Indexer Cluster Peer Configurations&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Distribute configurations and apps across peers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 - Managing and Monitoring Indexer Clusters&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enable replication for clustered indexes&lt;/li&gt;&lt;li&gt;Configure Monitoring Console for indexer cluster environment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Configuring Indexer Discovery on Forwarders&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure indexer discovery&lt;/li&gt;&lt;li&gt;Configure indexer acknowledgment&lt;/li&gt;&lt;li&gt;Configure forwarder site failover&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Deploying Search Head Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure a search head cluster&lt;/li&gt;&lt;li&gt;Connect clustered and non-clustered indexers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; Managing and Monitoring Search Head Clusters&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deploy configuration bundles to search head cluster members&lt;/li&gt;&lt;li&gt;Manage captaincy and member addition, removal and upgrades&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Using KV Store in a Search Head Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enable KV Store collection replication in a search head cluster&lt;/li&gt;&lt;li&gt;Monitor KV Store status with Monitoring Console&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:


- Intro to Splunk
- Using Fields (SUF)
- Introduction to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Splunk Enterprise System Administration (SESA)
- Splunk Enterprise Data Administration (SEDA)
- Troubleshooting Splunk Enterprise (TSE)
Additional courses and/or knowledge in these areas are also highly recommended:



- Enriching Data with Lookups (EDL)
- Data Models (SDM)</essentials_plain><audience_plain>Splunk administrators.</audience_plain><outline_plain>Module 1 – Overview of Large-scale Splunk Deployment



- Identify factors that affect large-scale deployment design
- Describe approaches to scaling Splunk Enterprise
- Configure Splunk License Manager
Module 2 – Deploying Single-site Indexer Clusters



- Identify indexer cluster states
- Define replication factor and search factor
- Implement a single-site indexer cluster
Module 3 – Deploying Multisite Indexer Clusters



- Define site replication factor and site search factor
- Define search affinity
- Implement a multisite indexer cluster
Module 4 – Updating Indexer Cluster Peer Configurations



- Distribute configurations and apps across peers
Module 5 - Managing and Monitoring Indexer Clusters



- Enable replication for clustered indexes
- Configure Monitoring Console for indexer cluster environment
Module 6 – Configuring Indexer Discovery on Forwarders



- Configure indexer discovery
- Configure indexer acknowledgment
- Configure forwarder site failover
Module 7 – Deploying Search Head Cluster



- Configure a search head cluster
- Connect clustered and non-clustered indexers
Module 8 – Managing and Monitoring Search Head Clusters



- Deploy configuration bundles to search head cluster members
- Manage captaincy and member addition, removal and upgrades
Module 9 – Using KV Store in a Search Head Cluster



- Enable KV Store collection replication in a search head cluster
- Monitor KV Store status with Monitoring Console</outline_plain><duration unit="d" days="2">2 days</duration><pricelist><price country="US" currency="USD">1500.00</price><price country="GB" currency="GBP">1250.00</price><price country="PL" currency="USD">1500.00</price><price country="DE" currency="EUR">1500.00</price><price country="AT" currency="EUR">1500.00</price><price country="SE" currency="EUR">1500.00</price><price country="CA" currency="CAD">2070.00</price><price country="CH" currency="CHF">1650.00</price><price country="NL" currency="EUR">1500.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue></miles></course>