<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="25903" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-tse" lastchanged="2026-01-13T17:43:08+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Troubleshooting Splunk Enterprise</title><productcode>TSE</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-TSE</fullproductcode><version>9.4</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working experience:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Introduction to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-seda&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Data Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEDA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Additional courses and/or knowledge in these areas are also highly recommended:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Administrators&lt;/p&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; Splunk Troubleshooting Methods and Tools&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Splunk Troubleshooting Approach&lt;/li&gt;&lt;li&gt;List Splunk Diagnostic Resources and Tools&lt;/li&gt;&lt;li&gt;Create and Splunk a Diag&lt;/li&gt;&lt;li&gt;Use RapidDiag&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Indexing Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discover Splunk Deployment Topology and its Server Roles&lt;/li&gt;&lt;li&gt;Identify Where to Check the Index-Time Pipeline Status&lt;/li&gt;&lt;li&gt;Use the metrics.log to Clarify the Index-Time Problem&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Input Configuration Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Data Input Issues&lt;/li&gt;&lt;li&gt;Troubleshooting Inputs with the Monitoring Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Deployment and Forwarder Problems&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployment Server Issues&lt;/li&gt;&lt;li&gt;Forwarding and Receiving Issues&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Search Management Problems&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Troubleshoot Distributed Search Issues&lt;/li&gt;&lt;li&gt;Identify Job Scheduling Problems&lt;/li&gt;&lt;li&gt;Learn to Diagnose Crashing Problems&lt;/li&gt;&lt;li&gt;Describe How to Prioritize Resources for Critical Splunk Processes&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; User Search Problems&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify the Types of Search Problems&lt;/li&gt;&lt;li&gt;Isolate and Troubleshoot Search Problems&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working experience:


- Intro to Splunk
- Using Fields (SUF)
- Introduction to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Splunk Enterprise System Administration (SESA)
- Splunk Enterprise Data Administration (SEDA)
Additional courses and/or knowledge in these areas are also highly recommended:


- Enriching Data with Lookups (EDL)
- Data Models (SDM)</essentials_plain><audience_plain>Administrators</audience_plain><outline_plain>Module 1 – Splunk Troubleshooting Methods and Tools


- Describe the Splunk Troubleshooting Approach
- List Splunk Diagnostic Resources and Tools
- Create and Splunk a Diag
- Use RapidDiag
Module 2 – Indexing Problems


- Discover Splunk Deployment Topology and its Server Roles
- Identify Where to Check the Index-Time Pipeline Status
- Use the metrics.log to Clarify the Index-Time Problem
Module 3 – Input Configuration Problems


- Data Input Issues
- Troubleshooting Inputs with the Monitoring Console
Module 4 – Deployment and Forwarder Problems



- Deployment Server Issues
- Forwarding and Receiving Issues
Module 5 – Search Management Problems



- Troubleshoot Distributed Search Issues
- Identify Job Scheduling Problems
- Learn to Diagnose Crashing Problems
- Describe How to Prioritize Resources for Critical Splunk Processes
Module 6 – User Search Problems



- Identify the Types of Search Problems
- Isolate and Troubleshoot Search Problems</outline_plain><duration unit="d" days="1">1 day</duration><pricelist><price country="US" currency="USD">1000.00</price><price country="GB" currency="GBP">835.00</price><price country="PL" currency="USD">1000.00</price><price country="DE" currency="EUR">1000.00</price><price country="AT" currency="EUR">1000.00</price><price country="SE" currency="EUR">1000.00</price><price country="CA" currency="CAD">1380.00</price><price country="CH" currency="CHF">1100.00</price><price country="NL" currency="EUR">1000.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">100.00</milesvalue></miles></course>