<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="25917" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-seda" lastchanged="2026-03-12T11:39:13+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Splunk Enterprise Data Administration</title><productcode>SEDA</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SEDA</fullproductcode><version>9.4</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Intro to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;Administrators&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; Get Data Into Splunk&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide an overview of Splunk&lt;/li&gt;&lt;li&gt;Describe the Splunk distributed model&lt;/li&gt;&lt;li&gt;Describe data input types and metadata settings&lt;/li&gt;&lt;li&gt;Configure initial input testing with Splunk Web&lt;/li&gt;&lt;li&gt;Test Indexes with input staging&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Configuration Files and Apps&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Splunk configuration files and directories&lt;/li&gt;&lt;li&gt;Describe index-time and search-time precedence&lt;/li&gt;&lt;li&gt;Validate and update configuration files&lt;/li&gt;&lt;li&gt;Explore Splunk apps and apps installation&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Configure Forwarders&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure Universal Forwarders&lt;/li&gt;&lt;li&gt;Configure Heavy Forwarders&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Customize Forwarder&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure intermediate forwarders&lt;/li&gt;&lt;li&gt;Identify additional forwarder options&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 - Manage Forwarders&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Splunk deployment server&lt;/li&gt;&lt;li&gt;Manage forwarders using deployment apps&lt;/li&gt;&lt;li&gt;Configure deployment clients and client groups&lt;/li&gt;&lt;li&gt;Monitor forwarder management activities&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt; Module 6 &amp;ndash; Monitor Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create file and directory monitor inputs&lt;/li&gt;&lt;li&gt;Use optional settings for monitor inputs&lt;/li&gt;&lt;li&gt;Deploy a remote monitor input&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Network Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create network (TCP and UDP) inputs&lt;/li&gt;&lt;li&gt;Describe optional settings for network inputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; Scripted Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a basic scripted input&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Agentless Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure Splunk HTTP Event Collector (HEC) agentless input&lt;/li&gt;&lt;li&gt;Describe Splunk App for Stream&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10 &amp;ndash; Operating System Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Linux-specific inputs&lt;/li&gt;&lt;li&gt;Identify Windows-specific inputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 11 &amp;ndash; Fine-tune Inputs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand the default processing that occurs during input phase&lt;/li&gt;&lt;li&gt;Configure input phase options&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 12 &amp;ndash; Parsing Phase and Data Preview&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand default processing during parsing phase&lt;/li&gt;&lt;li&gt;Optimize and configure event line breaking&lt;/li&gt;&lt;li&gt;Explain how timestamps and time zones are used&lt;/li&gt;&lt;li&gt;Use Data Preview to validate event create during parsing phase&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 13 &amp;ndash; Manipulating Input Data&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explore Splunk transformation methods&lt;/li&gt;&lt;li&gt;Create rulesets with Ingest Actions&lt;/li&gt;&lt;li&gt;Mask data with Ingest Action rules&lt;/li&gt;&lt;li&gt;Mask data with SEDCMD and TRANSFORMS&lt;/li&gt;&lt;li&gt;Override sourcetype or host base upon event values&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 14 - Route Input Data&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Filter data with Ingest Action rules&lt;/li&gt;&lt;li&gt;Route data with Ingest Action rules&lt;/li&gt;&lt;li&gt;Route data with Transforms&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 15 &amp;ndash; Support Knowledge Objects&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define default and custom search time field extractions&lt;/li&gt;&lt;li&gt;Identify the pros and cons of indexed time field extractions&lt;/li&gt;&lt;li&gt;Configure indexed field extractions&lt;/li&gt;&lt;li&gt;Describe default search-time extractions&lt;/li&gt;&lt;li&gt;Manage orphaned knowledge objects&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:



- Intro to Splunk
- Using Fields (SUF)
- Intro to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Enriching Data with Lookups (EDL)
- Data Models (SDM)
- Splunk Enterprise System Administration (SESA)</essentials_plain><audience_plain>- Administrators</audience_plain><outline_plain>Module 1 – Get Data Into Splunk


- Provide an overview of Splunk
- Describe the Splunk distributed model
- Describe data input types and metadata settings
- Configure initial input testing with Splunk Web
- Test Indexes with input staging
Module 2 – Configuration Files and Apps


- Identify Splunk configuration files and directories
- Describe index-time and search-time precedence
- Validate and update configuration files
- Explore Splunk apps and apps installation
Module 3 – Configure Forwarders


- Configure Universal Forwarders
- Configure Heavy Forwarders
Module 4 – Customize Forwarder


- Configure intermediate forwarders
- Identify additional forwarder options
Module 5 - Manage Forwarders


- Describe the Splunk deployment server
- Manage forwarders using deployment apps
- Configure deployment clients and client groups
- Monitor forwarder management activities
 Module 6 – Monitor Inputs


- Create file and directory monitor inputs
- Use optional settings for monitor inputs
- Deploy a remote monitor input
Module 7 – Network Inputs


- Create network (TCP and UDP) inputs
- Describe optional settings for network inputs
Module 8 – Scripted Inputs


- Create a basic scripted input
Module 9 – Agentless Inputs


- Configure Splunk HTTP Event Collector (HEC) agentless input
- Describe Splunk App for Stream
Module 10 – Operating System Inputs


- Identify Linux-specific inputs
- Identify Windows-specific inputs
Module 11 – Fine-tune Inputs


- Understand the default processing that occurs during input phase
- Configure input phase options
Module 12 – Parsing Phase and Data Preview


- Understand default processing during parsing phase
- Optimize and configure event line breaking
- Explain how timestamps and time zones are used
- Use Data Preview to validate event create during parsing phase
Module 13 – Manipulating Input Data


- Explore Splunk transformation methods
- Create rulesets with Ingest Actions
- Mask data with Ingest Action rules
- Mask data with SEDCMD and TRANSFORMS
- Override sourcetype or host base upon event values
Module 14 - Route Input Data


- Filter data with Ingest Action rules
- Route data with Ingest Action rules
- Route data with Transforms
Module 15 – Support Knowledge Objects


- Define default and custom search time field extractions
- Identify the pros and cons of indexed time field extractions
- Configure indexed field extractions
- Describe default search-time extractions
- Manage orphaned knowledge objects</outline_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="FR" currency="EUR">1600.00</price><price country="US" currency="USD">2250.00</price><price country="SI" currency="EUR">2250.00</price><price country="GR" currency="EUR">2250.00</price><price country="MK" currency="EUR">2250.00</price><price country="HU" currency="EUR">2250.00</price><price country="GB" currency="GBP">1875.00</price><price country="PL" currency="USD">2250.00</price><price country="DE" currency="EUR">2250.00</price><price country="AT" currency="EUR">2250.00</price><price country="SE" currency="EUR">2250.00</price><price country="CA" currency="CAD">3105.00</price><price country="CH" currency="CHF">2500.00</price><price country="NL" currency="EUR">2250.00</price><price country="IT" currency="USD">2250.00</price></pricelist><miles><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">225.00</milesvalue></miles></course>