<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="25904" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-tsc" lastchanged="2025-11-26T11:44:38+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Transitioning to Splunk Cloud</title><productcode>TSC</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-TSC</fullproductcode><version>9.4</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working
knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Intro to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-seda&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Data Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEDA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Additional courses and/or knowledge in these areas are also highly recommended:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Splunk Enterprise Administrators&lt;/p&gt;</audience><contents>&lt;p&gt;This course is for experienced on-prem administrators and anyone needing to ramp-up on Splunk Cloud to get more knowledge and experience of managing Splunk Cloud instances.&lt;/p&gt;
&lt;p&gt;The course discusses the differentiators between on-prem Splunk and the different Splunk Cloud offerings. Modules include topics on how to migrate data collection and ingest from on-prem Splunk to Splunk Cloud as well as highlighting Splunk Cloud specific differences and best practices to manage a productive Splunk SaaS deployment. For Splunk Administrators who have undertaken the System and Data Administration learning pathways, this course highlights key differences between Splunk Enterprise deployed on-premises and Splunk Enterprise Cloud to allow them to ramp up their data and system management skills to transition to Splunk Cloud. The hands-on lab provides access to and experience of managing a Splunk Cloud instance.&lt;/p&gt;
&lt;p&gt;Note: Splunk Cloud Administration and Transitioning to Splunk Cloud SHOULD NOT be taken together as both are designed to develop Splunk Cloud-specific skills and as such there is some overlap.&lt;/p&gt;
&lt;p&gt; &lt;strong&gt;Please note that this course may run over two days, with 4.5 hour sessions each day.&lt;/strong&gt;&lt;/p&gt;</contents><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; Splunk Cloud Overview&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Splunk and Splunk Cloud features and topology&lt;/li&gt;&lt;li&gt;Identify Splunk Cloud administrator tasks&lt;/li&gt;&lt;li&gt;Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience&lt;/li&gt;&lt;li&gt;Secure Splunk deployments best practices&lt;/li&gt;&lt;li&gt;Explain Splunk Cloud data ingestion strategies&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Splunk Cloud Migration&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand the Splunk Cloud migration journey&lt;/li&gt;&lt;li&gt;Determine Splunk Cloud migration readiness&lt;/li&gt;&lt;li&gt;Identify Splunk Cloud migration preparation tasks, strategies, and possible challenges&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Managing Users&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Splunk Cloud authentication options&lt;/li&gt;&lt;li&gt;Add Splunk users using native authentication&lt;/li&gt;&lt;li&gt;Create a custom role&lt;/li&gt;&lt;li&gt;Integrate Splunk with LDAP, Active Directory or SAML&lt;/li&gt;&lt;li&gt;Use Workload Management to manage user resource usage&lt;/li&gt;&lt;li&gt;Manage users in Splunk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Managing Indexes&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand cloud indexing strategy&lt;/li&gt;&lt;li&gt;Define and create indexes&lt;/li&gt;&lt;li&gt;Manage data retention and archiving&lt;/li&gt;&lt;li&gt;Delete and mask data from an index&lt;/li&gt;&lt;li&gt;Monitor indexing activities&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Managing Apps&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review the process for installing apps&lt;/li&gt;&lt;li&gt;Define the purpose of private apps&lt;/li&gt;&lt;li&gt;Upload private apps&lt;/li&gt;&lt;li&gt;Describe how apps are managed&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Configuring Forwarders&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List Splunk forwarder types&lt;/li&gt;&lt;li&gt;Understand the role of forwarders&lt;/li&gt;&lt;li&gt;Configure a forwarder to send data to Splunk Cloud&lt;/li&gt;&lt;li&gt;Test the forwarder connection&lt;/li&gt;&lt;li&gt;Describe optional forwarder settings&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Common Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe forwarder inputs such as files and directories&lt;/li&gt;&lt;li&gt;Create REST API inputs&lt;/li&gt;&lt;li&gt;Create a basic scripted input&lt;/li&gt;&lt;li&gt;Create Splunk HTTP Event Collector (HEC) agentless inputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; Additional Inputs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand how inputs are managed using apps or add-ons&lt;/li&gt;&lt;li&gt;Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Using Ingest Actions&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explore Splunk transformation methods&lt;/li&gt;&lt;li&gt;Create and manage rulesets with Ingest Actions&lt;/li&gt;&lt;li&gt;Mask, filter and route data with Ingest Action rules&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10 &amp;ndash; Managing Splunk Cloud&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Secure ingest with Splunk Cloud Private Connectivity with AWS&lt;/li&gt;&lt;li&gt;Describe Federated Search functionality&lt;/li&gt;&lt;li&gt;Describe Splunk connected experience apps such as Splunk Secure Gateway&lt;/li&gt;&lt;li&gt;Monitor and manage resource utilization by business units and users using Splunk App for Chargeback&lt;/li&gt;&lt;li&gt;Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 11 &amp;ndash; Supporting Splunk Cloud&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Know how to isolate problems before contacting Splunk Cloud Support&lt;/li&gt;&lt;li&gt;Use Isolation Troubleshooting&lt;/li&gt;&lt;li&gt;Define the process for engaging Splunk Support&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Appendix&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explore Splunk security fundamentals&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working
knowledge:


- Intro to Splunk
- Using Fields (SUF)
- Intro to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Splunk Enterprise System Administration (SESA)
- Splunk Enterprise Data Administration (SEDA)
Additional courses and/or knowledge in these areas are also highly recommended:



- Enriching Data with Lookups (EDL)
- Data Models (SDM)</essentials_plain><audience_plain>Splunk Enterprise Administrators</audience_plain><contents_plain>This course is for experienced on-prem administrators and anyone needing to ramp-up on Splunk Cloud to get more knowledge and experience of managing Splunk Cloud instances.

The course discusses the differentiators between on-prem Splunk and the different Splunk Cloud offerings. Modules include topics on how to migrate data collection and ingest from on-prem Splunk to Splunk Cloud as well as highlighting Splunk Cloud specific differences and best practices to manage a productive Splunk SaaS deployment. For Splunk Administrators who have undertaken the System and Data Administration learning pathways, this course highlights key differences between Splunk Enterprise deployed on-premises and Splunk Enterprise Cloud to allow them to ramp up their data and system management skills to transition to Splunk Cloud. The hands-on lab provides access to and experience of managing a Splunk Cloud instance.

Note: Splunk Cloud Administration and Transitioning to Splunk Cloud SHOULD NOT be taken together as both are designed to develop Splunk Cloud-specific skills and as such there is some overlap.

 Please note that this course may run over two days, with 4.5 hour sessions each day.</contents_plain><outline_plain>Module 1 – Splunk Cloud Overview



- Describe Splunk and Splunk Cloud features and topology
- Identify Splunk Cloud administrator tasks
- Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience
- Secure Splunk deployments best practices
- Explain Splunk Cloud data ingestion strategies
Module 2 – Splunk Cloud Migration



- Understand the Splunk Cloud migration journey
- Determine Splunk Cloud migration readiness
- Identify Splunk Cloud migration preparation tasks, strategies, and possible challenges
Module 3 – Managing Users



- Identify Splunk Cloud authentication options
- Add Splunk users using native authentication
- Create a custom role
- Integrate Splunk with LDAP, Active Directory or SAML
- Use Workload Management to manage user resource usage
- Manage users in Splunk
Module 4 – Managing Indexes



- Understand cloud indexing strategy
- Define and create indexes
- Manage data retention and archiving
- Delete and mask data from an index
- Monitor indexing activities
Module 5 – Managing Apps



- Review the process for installing apps
- Define the purpose of private apps
- Upload private apps
- Describe how apps are managed
Module 6 – Configuring Forwarders



- List Splunk forwarder types
- Understand the role of forwarders
- Configure a forwarder to send data to Splunk Cloud
- Test the forwarder connection
- Describe optional forwarder settings
Module 7 – Common Inputs



- Describe forwarder inputs such as files and directories
- Create REST API inputs
- Create a basic scripted input
- Create Splunk HTTP Event Collector (HEC) agentless inputs
Module 8 – Additional Inputs



- Understand how inputs are managed using apps or add-ons
- Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub
Module 9 – Using Ingest Actions



- Explore Splunk transformation methods
- Create and manage rulesets with Ingest Actions
- Mask, filter and route data with Ingest Action rules
Module 10 – Managing Splunk Cloud



- Secure ingest with Splunk Cloud Private Connectivity with AWS
- Describe Federated Search functionality
- Describe Splunk connected experience apps such as Splunk Secure Gateway
- Monitor and manage resource utilization by business units and users using Splunk App for Chargeback
- Perform self-service administrative tasks in Splunk Cloud using the Admin Config Service
Module 11 – Supporting Splunk Cloud



- Know how to isolate problems before contacting Splunk Cloud Support
- Use Isolation Troubleshooting
- Define the process for engaging Splunk Support
Appendix



- Explore Splunk security fundamentals</outline_plain><duration unit="d" days="0">9 hours</duration><pricelist><price country="US" currency="USD">1000.00</price><price country="GB" currency="GBP">835.00</price><price country="PL" currency="USD">1000.00</price><price country="DE" currency="EUR">1000.00</price><price country="CA" currency="CAD">1380.00</price><price country="CH" currency="CHF">1100.00</price><price country="NL" currency="EUR">1000.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue></miles></course>