{"course":{"productid":29607,"modality":1,"active":true,"language":"fr","title":"Splunk Enterprise Architect Fast Start","productcode":"ARCH-FT","vendorcode":"SP","vendorname":"Splunk","fullproductcode":"SP-ARCH-FT","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.ch\/course\/splunk-arch-ft","objective":"<p>At the end of this course, you should be able to :<\/p>\n<ul>\n<li>Understand Splunk Troubleshooting Methods and Tools<\/li><li>Index Problems<\/li><li>Input Configuration Problems<\/li><li>Understand Deployment Problems<\/li><li>Understand License, Upgrade, and User Management Problems<\/li><li>Understand Search Management Problems<\/li><li>User Search Problems<\/li><li>Understand the Splunk Support Model and its resources<\/li><li>Identify the best practices for troubleshooting Splunk Enterprise<\/li><li>List ways to gather useful Splunk diagnostic information<\/li><li>Use Splunk diagnostic tools<\/li><li>Identify common Splunk technical issues and solve them<\/li><li>Understand Requirements definition<\/li><li>Understand Index and resource planning<\/li><li>Understand Cluster<\/li><li>Understand Forwarder and Deployment<\/li><li>Integration<\/li><li>Understand Performance Monitoring and Tuning<\/li><li>Understand Large-scale Splunk Deployment<\/li><li>Understand Single-site Indexer Cluster<\/li><li>Understand Indexer Cluster Management and Administration<\/li><li>Understand Forwarder Configuration<\/li><li>Understand Search Head Cluster<\/li><li>Understand Search Head Cluster Management and Administration<\/li><li>Understand KV Store Collection and Lookup Management<\/li><li>Understand SmartStore Implementation<\/li><\/ul>","essentials":"<p>Splunk Core Certified Power User AND Splunk Enterprise Certified Admin.<\/p>\n<p><strong>Hard pre-req:<\/strong> The three ILTs in this path PLUS the Splunk Enterprise Practical Lab.<\/p>","audience":"<p>Splunk administrators\nEexperienced Splunk Enterprise administrator who is new to Splunk Clusters<\/p>","contents":"<h4>Troubleshooting Splunk Enterprise<\/h4><p>\n<strong>Module 1 &ndash; Splunk Troubleshooting Methods and Tools<\/strong><\/p>\n<ul>\n<li>Describe the Splunk Troubleshooting Approach<\/li><li>List Splunk Diagnostic Resources and Tools<\/li><li>Create and Splunk a Diag<\/li><li>Use RapidDiag<\/li><\/ul><p><strong>Module 2 &ndash; Indexing Problems<\/strong><\/p>\n<ul>\n<li>Discover Splunk Deployment Topology and its Server Roles<\/li><li>Identify Where to Check the Index-Time Pipeline Status<\/li><li>Use the metrics.log to Clarify the Index-Time Problem<\/li><\/ul><p><strong>Module 3 &ndash; Input Configuration Problems<\/strong><\/p>\n<ul>\n<li>Data Input Issues<\/li><li>Troubleshooting Inputs with the Monitoring Console<\/li><\/ul><p><strong>Module 4 &ndash; Deployment and Forwarder Problems<\/strong><\/p>\n<ul>\n<li>Deployment Server Issues<\/li><li>Forwarding and Receiving Issues<\/li><\/ul><p><strong>Module 5 &ndash; License, Upgrade, and User Management Problems<\/strong><\/p>\n<ul>\n<li>Installation Issues<\/li><li>Upgrade Considerations<\/li><li>Splunk Licensing Issues<\/li><li>Splunk Roles and User Management Issues<\/li><\/ul><p><strong>Module 6 &ndash; Search Head Management Problems<\/strong><\/p>\n<ul>\n<li>Troubleshoot Distributed Search Issues<\/li><li>Identify Job Scheduling Problems<\/li><li>Learn to Diagnose Crashing Problems<\/li><li>Describe How to Prioritize Resources for Critical Splunk Processes<\/li><\/ul><p><strong>Module 7 &ndash; User Search Problems<\/strong><\/p>\n<ul>\n<li>Identify the Types of Search Problems<\/li><li>Isolate and Troubleshoot Search Problems<\/li><\/ul><h5>Splunk Enterprise Cluster Administration<\/h5><p>\n<strong>Module 1 &ndash; Splunk Troubleshooting Methods and Tools<\/strong>\n<\/p>\n<ul>\n<li>Deployment Design Factors<\/li><li>How Splunk Enterprise can scale<\/li><li>Splunk License Master<\/li><li>Splunk 9.0 Security<\/li><\/ul><p><strong>Module 2 &ndash; Single-site Indexer Cluster<\/strong>\n<\/p>\n<ul>\n<li>How Splunk Single-Site Indexer Clusters Work<\/li><li>Indexer Cluster Components and Terms<\/li><li>Splunk single-site Indexer Cluster Configuration<\/li><li>Splunk Indexer Cluster Log Channels<\/li><\/ul><p><strong>Module 3 &ndash; Multisite Indexer Cluster<\/strong>\n<\/p>\n<ul>\n<li>How Splunk Multisite Indexer Clusters Work<\/li><li>Multisite Indexer Cluster Terms<\/li><li>Multisite Indexer Cluster Configuration<\/li><li>Optional Multisite Indexer Cluster Configurations<\/li><\/ul><p><strong>Module 4 &ndash; Indexer Cluster Management and Administration<\/strong>\n<\/p>\n<ul>\n<li>Peer Offline and Decommission<\/li><li>Master App Bundles<\/li><li>Indexer Cluster Storage Utilization Options<\/li><li>Site Mapping<\/li><li>Monitoring Console for Indexer Cluster Environment<\/li><li>Cluster Manager Redundancy<\/li><\/ul><p><strong>Module 5 &ndash; Forwarder Management<\/strong>\n<\/p>\n<ul>\n<li>Indexer Discovery<\/li><li>Optional Indexer Discovery Configurations<\/li><li>Volume-Based Forwarder Load Balancing<\/li><\/ul><p><strong>Module 6 &ndash; Search Head Cluster<\/strong>\n<\/p>\n<ul>\n<li>Search Head Cluster Architecture<\/li><li>Search Head Cluster Configuration<\/li><li>Captaincy Identification and Cluster Status<\/li><li>Search Head Cluster Settings<\/li><\/ul><p><strong>Module 7 &ndash; Search Head Cluster Management<\/strong>\n<\/p>\n<ul>\n<li>Search Head Cluster Deployer<\/li><li>Captaincy Transfer<\/li><li>Search Head Member Addition and Decommissioning<\/li><li>Monitoring Console for Search Head Cluster<\/li><\/ul><p><strong>Module 8 &ndash; KV Store Collection and Lookup Management<\/strong>\n<\/p>\n<ul>\n<li>KV Store Collection in Splunk Clusters<\/li><li>KV Store Monitoring with Monitoring Console<\/li><\/ul><p><strong>Module 9 &ndash; Introduction to Smart Store<\/strong>\n<\/p>\n<ul>\n<li>SmartStore Deployment Use Cases<\/li><li>SmartStore Architecture Overview<\/li><li>Enable SmartStore in Indexer Cluster<\/li><li>Monitor SmartStore Status<\/li><\/ul><h4>Architecting Splunk Enterprise Deployments<\/h4><p>\n<strong>Module 1 &ndash; Introduction<\/strong><\/p>\n<ul>\n<li>Overview of the Splunk deployment planning process and associated tools<\/li><\/ul><p><strong>Module 2 &ndash; Project Requirements<\/strong><\/p>\n<ul>\n<li>Identify critical information about environment, volume, users, and requirements<\/li><li>Review checklists and resources to aid in collecting requirements<\/li><\/ul><p><strong>Module 3 &ndash; Infrastructure Planning: Index Design<\/strong><\/p>\n<ul>\n<li>Design and size indexes<\/li><li>Estimate storage requirements<\/li><li>Identify relevant apps<\/li><\/ul>\n<p><strong>Module 4 &ndash; Infrastructure Planning: Resource Planning<\/strong><\/p>\n<ul>\n<li>List sizing factors for servers<\/li><li>Describe how reference hardware is used to scale deployments<\/li><li>Identify the impact of clustering for index replication and for search heads<\/li><\/ul><p><strong>Module 5- Clustering Overview<\/strong><\/p>\n<ul>\n<li>Describe the different clustering capabilities<\/li><li>Introduce the concepts of indexer and search head clustering<\/li><\/ul><p><strong>Module 6 - Forwarder and Deployment Best Practices<\/strong><\/p>\n<ul>\n<li>Review types of forwarders<\/li><li>Describe how to manage forwarder installation<\/li><li>Review configuration management for all Splunk components, using Splunk deployment tools<\/li><li>Provide best practices for a Splunk deployment<\/li><\/ul><p><strong>Module 7 - Integration <\/strong><\/p>\n<ul>\n<li>Describe integration methods<\/li><li>Identify common integration points<\/li><\/ul><p><strong>Module  8 &ndash; Performance Monitoring and Tuning<\/strong><\/p>\n<ul>\n<li>Use the Monitoring Console to track the performance of your test environment<\/li><li>List options to fine tune performance for production environment<\/li><\/ul><p><strong>Module 9 &ndash; Use Cases<\/strong><\/p>\n<ul>\n<li>Provide example architecture topologies<\/li><li>Discuss different architecture options based on use case<\/li><\/ul>","outline":"<h4>Troubleshooting Splunk Enterprise<\/h4><p>\n<strong>Module 1 &ndash; Splunk Troubleshooting Methods and Tools<\/strong><\/p>\n<ul>\n<li>Describe the Splunk Troubleshooting Approach<\/li><li>List Splunk Diagnostic Resources and Tools<\/li><li>Create and Splunk a Diag<\/li><li>Use RapidDiag<\/li><\/ul><p><strong>Module 2 &ndash; Indexing Problems<\/strong><\/p>\n<ul>\n<li>Discover Splunk Deployment Topology and its Server Roles<\/li><li>Identify Where to Check the Index-Time Pipeline Status<\/li><li>Use the metrics.log to Clarify the Index-Time Problem<\/li><\/ul><p><strong>Module 3 &ndash; Input Configuration Problems<\/strong><\/p>\n<ul>\n<li>Data Input Issues<\/li><li>Troubleshooting Inputs with the Monitoring Console<\/li><\/ul><p><strong>Module 4 &ndash; Deployment and Forwarder Problems<\/strong><\/p>\n<ul>\n<li>Deployment Server Issues<\/li><li>Forwarding and Receiving Issues<\/li><\/ul><p><strong>Module 5 &ndash; License, Upgrade, and User Management Problems<\/strong><\/p>\n<ul>\n<li>Installation Issues<\/li><li>Upgrade Considerations<\/li><li>Splunk Licensing Issues<\/li><li>Splunk Roles and User Management Issues<\/li><\/ul><p><strong>Module 6 &ndash; Search Head Management Problems<\/strong><\/p>\n<ul>\n<li>Troubleshoot Distributed Search Issues<\/li><li>Identify Job Scheduling Problems<\/li><li>Learn to Diagnose Crashing Problems<\/li><li>Describe How to Prioritize Resources for Critical Splunk Processes<\/li><\/ul><p><strong>Module 7 &ndash; User Search Problems<\/strong><\/p>\n<ul>\n<li>Identify the Types of Search Problems<\/li><li>Isolate and Troubleshoot Search Problems<\/li><\/ul><h5>Splunk Enterprise Cluster Administration<\/h5><p>\n<strong>Module 1 &ndash; Splunk Troubleshooting Methods and Tools<\/strong>\n<\/p>\n<ul>\n<li>Deployment Design Factors<\/li><li>How Splunk Enterprise can scale<\/li><li>Splunk License Master<\/li><li>Splunk 9.0 Security<\/li><\/ul><p><strong>Module 2 &ndash; Single-site Indexer Cluster<\/strong>\n<\/p>\n<ul>\n<li>How Splunk Single-Site Indexer Clusters Work<\/li><li>Indexer Cluster Components and Terms<\/li><li>Splunk single-site Indexer Cluster Configuration<\/li><li>Splunk Indexer Cluster Log Channels<\/li><\/ul><p><strong>Module 3 &ndash; Multisite Indexer Cluster<\/strong>\n<\/p>\n<ul>\n<li>How Splunk Multisite Indexer Clusters Work<\/li><li>Multisite Indexer Cluster Terms<\/li><li>Multisite Indexer Cluster Configuration<\/li><li>Optional Multisite Indexer Cluster Configurations<\/li><\/ul><p><strong>Module 4 &ndash; Indexer Cluster Management and Administration<\/strong>\n<\/p>\n<ul>\n<li>Peer Offline and Decommission<\/li><li>Master App Bundles<\/li><li>Indexer Cluster Storage Utilization Options<\/li><li>Site Mapping<\/li><li>Monitoring Console for Indexer Cluster Environment<\/li><li>Cluster Manager Redundancy<\/li><\/ul><p><strong>Module 5 &ndash; Forwarder Management<\/strong>\n<\/p>\n<ul>\n<li>Indexer Discovery<\/li><li>Optional Indexer Discovery Configurations<\/li><li>Volume-Based Forwarder Load Balancing<\/li><\/ul><p><strong>Module 6 &ndash; Search Head Cluster<\/strong>\n<\/p>\n<ul>\n<li>Search Head Cluster Architecture<\/li><li>Search Head Cluster Configuration<\/li><li>Captaincy Identification and Cluster Status<\/li><li>Search Head Cluster Settings<\/li><\/ul><p><strong>Module 7 &ndash; Search Head Cluster Management<\/strong>\n<\/p>\n<ul>\n<li>Search Head Cluster Deployer<\/li><li>Captaincy Transfer<\/li><li>Search Head Member Addition and Decommissioning<\/li><li>Monitoring Console for Search Head Cluster<\/li><\/ul><p><strong>Module 8 &ndash; KV Store Collection and Lookup Management<\/strong>\n<\/p>\n<ul>\n<li>KV Store Collection in Splunk Clusters<\/li><li>KV Store Monitoring with Monitoring Console<\/li><\/ul><p><strong>Module 9 &ndash; Introduction to Smart Store<\/strong>\n<\/p>\n<ul>\n<li>SmartStore Deployment Use Cases<\/li><li>SmartStore Architecture Overview<\/li><li>Enable SmartStore in Indexer Cluster<\/li><li>Monitor SmartStore Status<\/li><\/ul><h4>Architecting Splunk Enterprise Deployments<\/h4><p>\n<strong>Module 1 &ndash; Introduction<\/strong><\/p>\n<ul>\n<li>Overview of the Splunk deployment planning process and associated tools<\/li><\/ul><p><strong>Module 2 &ndash; Project Requirements<\/strong><\/p>\n<ul>\n<li>Identify critical information about environment, volume, users, and requirements<\/li><li>Review checklists and resources to aid in collecting requirements<\/li><\/ul><p><strong>Module 3 &ndash; Infrastructure Planning: Index Design<\/strong><\/p>\n<ul>\n<li>Design and size indexes<\/li><li>Estimate storage requirements<\/li><li>Identify relevant apps<\/li><\/ul>\n<p><strong>Module 4 &ndash; Infrastructure Planning: Resource Planning<\/strong><\/p>\n<ul>\n<li>List sizing factors for servers<\/li><li>Describe how reference hardware is used to scale deployments<\/li><li>Identify the impact of clustering for index replication and for search heads<\/li><\/ul><p><strong>Module 5- Clustering Overview<\/strong><\/p>\n<ul>\n<li>Describe the different clustering capabilities<\/li><li>Introduce the concepts of indexer and search head clustering<\/li><\/ul><p><strong>Module 6 - Forwarder and Deployment Best Practices<\/strong><\/p>\n<ul>\n<li>Review types of forwarders<\/li><li>Describe how to manage forwarder installation<\/li><li>Review configuration management for all Splunk components, using Splunk deployment tools<\/li><li>Provide best practices for a Splunk deployment<\/li><\/ul><p><strong>Module 7 - Integration <\/strong><\/p>\n<ul>\n<li>Describe integration methods<\/li><li>Identify common integration points<\/li><\/ul><p><strong>Module  8 &ndash; Performance Monitoring and Tuning<\/strong><\/p>\n<ul>\n<li>Use the Monitoring Console to track the performance of your test environment<\/li><li>List options to fine tune performance for production environment<\/li><\/ul><p><strong>Module 9 &ndash; Use Cases<\/strong><\/p>\n<ul>\n<li>Provide example architecture topologies<\/li><li>Discuss different architecture options based on use case<\/li><\/ul>","summary":"<p>This series consists of three modules totaling 36 hours of content and leads to the Splunk Enterprise Certified Architect certification.<br\/>\n<br\/>\nThe series consists of the following courses:<br\/>\n<\/p>\n<ul>\n<li><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-tse\">Troubleshooting Splunk Enterprise <span class=\"fl-prod-pcode\">(TSE)<\/span><\/a><\/li><li><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-scla\">Splunk Enterprise Cluster Administration <span class=\"fl-prod-pcode\">(SCLA)<\/span><\/a><\/li><li><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-ased\">Architecting Splunk Enterprise Deployments <span class=\"fl-prod-pcode\">(ASED)<\/span><\/a><\/li><\/ul>","objective_plain":"At the end of this course, you should be able to :\n\n\n- Understand Splunk Troubleshooting Methods and Tools\n- Index Problems\n- Input Configuration Problems\n- Understand Deployment Problems\n- Understand License, Upgrade, and User Management Problems\n- Understand Search Management Problems\n- User Search Problems\n- Understand the Splunk Support Model and its resources\n- Identify the best practices for troubleshooting Splunk Enterprise\n- List ways to gather useful Splunk diagnostic information\n- Use Splunk diagnostic tools\n- Identify common Splunk technical issues and solve them\n- Understand Requirements definition\n- Understand Index and resource planning\n- Understand Cluster\n- Understand Forwarder and Deployment\n- Integration\n- Understand Performance Monitoring and Tuning\n- Understand Large-scale Splunk Deployment\n- Understand Single-site Indexer Cluster\n- Understand Indexer Cluster Management and Administration\n- Understand Forwarder Configuration\n- Understand Search Head Cluster\n- Understand Search Head Cluster Management and Administration\n- Understand KV Store Collection and Lookup Management\n- Understand SmartStore Implementation","essentials_plain":"Splunk Core Certified Power User AND Splunk Enterprise Certified Admin.\n\nHard pre-req: The three ILTs in this path PLUS the Splunk Enterprise Practical Lab.","audience_plain":"Splunk administrators\nEexperienced Splunk Enterprise administrator who is new to Splunk Clusters","contents_plain":"Troubleshooting Splunk Enterprise\n\n\nModule 1 \u2013 Splunk Troubleshooting Methods and Tools\n\n\n- Describe the Splunk Troubleshooting Approach\n- List Splunk Diagnostic Resources and Tools\n- Create and Splunk a Diag\n- Use RapidDiag\nModule 2 \u2013 Indexing Problems\n\n\n- Discover Splunk Deployment Topology and its Server Roles\n- Identify Where to Check the Index-Time Pipeline Status\n- Use the metrics.log to Clarify the Index-Time Problem\nModule 3 \u2013 Input Configuration Problems\n\n\n- Data Input Issues\n- Troubleshooting Inputs with the Monitoring Console\nModule 4 \u2013 Deployment and Forwarder Problems\n\n\n- Deployment Server Issues\n- Forwarding and Receiving Issues\nModule 5 \u2013 License, Upgrade, and User Management Problems\n\n\n- Installation Issues\n- Upgrade Considerations\n- Splunk Licensing Issues\n- Splunk Roles and User Management Issues\nModule 6 \u2013 Search Head Management Problems\n\n\n- Troubleshoot Distributed Search Issues\n- Identify Job Scheduling Problems\n- Learn to Diagnose Crashing Problems\n- Describe How to Prioritize Resources for Critical Splunk Processes\nModule 7 \u2013 User Search Problems\n\n\n- Identify the Types of Search Problems\n- Isolate and Troubleshoot Search Problems\nSplunk Enterprise Cluster Administration\n\n\nModule 1 \u2013 Splunk Troubleshooting Methods and Tools\n\n\n\n- Deployment Design Factors\n- How Splunk Enterprise can scale\n- Splunk License Master\n- Splunk 9.0 Security\nModule 2 \u2013 Single-site Indexer Cluster\n\n\n\n- How Splunk Single-Site Indexer Clusters Work\n- Indexer Cluster Components and Terms\n- Splunk single-site Indexer Cluster Configuration\n- Splunk Indexer Cluster Log Channels\nModule 3 \u2013 Multisite Indexer Cluster\n\n\n\n- How Splunk Multisite Indexer Clusters Work\n- Multisite Indexer Cluster Terms\n- Multisite Indexer Cluster Configuration\n- Optional Multisite Indexer Cluster Configurations\nModule 4 \u2013 Indexer Cluster Management and Administration\n\n\n\n- Peer Offline and Decommission\n- Master App Bundles\n- Indexer Cluster Storage Utilization Options\n- Site Mapping\n- Monitoring Console for Indexer Cluster Environment\n- Cluster Manager Redundancy\nModule 5 \u2013 Forwarder Management\n\n\n\n- Indexer Discovery\n- Optional Indexer Discovery Configurations\n- Volume-Based Forwarder Load Balancing\nModule 6 \u2013 Search Head Cluster\n\n\n\n- Search Head Cluster Architecture\n- Search Head Cluster Configuration\n- Captaincy Identification and Cluster Status\n- Search Head Cluster Settings\nModule 7 \u2013 Search Head Cluster Management\n\n\n\n- Search Head Cluster Deployer\n- Captaincy Transfer\n- Search Head Member Addition and Decommissioning\n- Monitoring Console for Search Head Cluster\nModule 8 \u2013 KV Store Collection and Lookup Management\n\n\n\n- KV Store Collection in Splunk Clusters\n- KV Store Monitoring with Monitoring Console\nModule 9 \u2013 Introduction to Smart Store\n\n\n\n- SmartStore Deployment Use Cases\n- SmartStore Architecture Overview\n- Enable SmartStore in Indexer Cluster\n- Monitor SmartStore Status\nArchitecting Splunk Enterprise Deployments\n\n\nModule 1 \u2013 Introduction\n\n\n- Overview of the Splunk deployment planning process and associated tools\nModule 2 \u2013 Project Requirements\n\n\n- Identify critical information about environment, volume, users, and requirements\n- Review checklists and resources to aid in collecting requirements\nModule 3 \u2013 Infrastructure Planning: Index Design\n\n\n- Design and size indexes\n- Estimate storage requirements\n- Identify relevant apps\n\nModule 4 \u2013 Infrastructure Planning: Resource Planning\n\n\n- List sizing factors for servers\n- Describe how reference hardware is used to scale deployments\n- Identify the impact of clustering for index replication and for search heads\nModule 5- Clustering Overview\n\n\n- Describe the different clustering capabilities\n- Introduce the concepts of indexer and search head clustering\nModule 6 - Forwarder and Deployment Best Practices\n\n\n- Review types of forwarders\n- Describe how to manage forwarder installation\n- Review configuration management for all Splunk components, using Splunk deployment tools\n- Provide best practices for a Splunk deployment\nModule 7 - Integration \n\n\n- Describe integration methods\n- Identify common integration points\nModule  8 \u2013 Performance Monitoring and Tuning\n\n\n- Use the Monitoring Console to track the performance of your test environment\n- List options to fine tune performance for production environment\nModule 9 \u2013 Use Cases\n\n\n- Provide example architecture topologies\n- Discuss different architecture options based on use case","outline_plain":"Troubleshooting Splunk Enterprise\n\n\nModule 1 \u2013 Splunk Troubleshooting Methods and Tools\n\n\n- Describe the Splunk Troubleshooting Approach\n- List Splunk Diagnostic Resources and Tools\n- Create and Splunk a Diag\n- Use RapidDiag\nModule 2 \u2013 Indexing Problems\n\n\n- Discover Splunk Deployment Topology and its Server Roles\n- Identify Where to Check the Index-Time Pipeline Status\n- Use the metrics.log to Clarify the Index-Time Problem\nModule 3 \u2013 Input Configuration Problems\n\n\n- Data Input Issues\n- Troubleshooting Inputs with the Monitoring Console\nModule 4 \u2013 Deployment and Forwarder Problems\n\n\n- Deployment Server Issues\n- Forwarding and Receiving Issues\nModule 5 \u2013 License, Upgrade, and User Management Problems\n\n\n- Installation Issues\n- Upgrade Considerations\n- Splunk Licensing Issues\n- Splunk Roles and User Management Issues\nModule 6 \u2013 Search Head Management Problems\n\n\n- Troubleshoot Distributed Search Issues\n- Identify Job Scheduling Problems\n- Learn to Diagnose Crashing Problems\n- Describe How to Prioritize Resources for Critical Splunk Processes\nModule 7 \u2013 User Search Problems\n\n\n- Identify the Types of Search Problems\n- Isolate and Troubleshoot Search Problems\nSplunk Enterprise Cluster Administration\n\n\nModule 1 \u2013 Splunk Troubleshooting Methods and Tools\n\n\n\n- Deployment Design Factors\n- How Splunk Enterprise can scale\n- Splunk License Master\n- Splunk 9.0 Security\nModule 2 \u2013 Single-site Indexer Cluster\n\n\n\n- How Splunk Single-Site Indexer Clusters Work\n- Indexer Cluster Components and Terms\n- Splunk single-site Indexer Cluster Configuration\n- Splunk Indexer Cluster Log Channels\nModule 3 \u2013 Multisite Indexer Cluster\n\n\n\n- How Splunk Multisite Indexer Clusters Work\n- Multisite Indexer Cluster Terms\n- Multisite Indexer Cluster Configuration\n- Optional Multisite Indexer Cluster Configurations\nModule 4 \u2013 Indexer Cluster Management and Administration\n\n\n\n- Peer Offline and Decommission\n- Master App Bundles\n- Indexer Cluster Storage Utilization Options\n- Site Mapping\n- Monitoring Console for Indexer Cluster Environment\n- Cluster Manager Redundancy\nModule 5 \u2013 Forwarder Management\n\n\n\n- Indexer Discovery\n- Optional Indexer Discovery Configurations\n- Volume-Based Forwarder Load Balancing\nModule 6 \u2013 Search Head Cluster\n\n\n\n- Search Head Cluster Architecture\n- Search Head Cluster Configuration\n- Captaincy Identification and Cluster Status\n- Search Head Cluster Settings\nModule 7 \u2013 Search Head Cluster Management\n\n\n\n- Search Head Cluster Deployer\n- Captaincy Transfer\n- Search Head Member Addition and Decommissioning\n- Monitoring Console for Search Head Cluster\nModule 8 \u2013 KV Store Collection and Lookup Management\n\n\n\n- KV Store Collection in Splunk Clusters\n- KV Store Monitoring with Monitoring Console\nModule 9 \u2013 Introduction to Smart Store\n\n\n\n- SmartStore Deployment Use Cases\n- SmartStore Architecture Overview\n- Enable SmartStore in Indexer Cluster\n- Monitor SmartStore Status\nArchitecting Splunk Enterprise Deployments\n\n\nModule 1 \u2013 Introduction\n\n\n- Overview of the Splunk deployment planning process and associated tools\nModule 2 \u2013 Project Requirements\n\n\n- Identify critical information about environment, volume, users, and requirements\n- Review checklists and resources to aid in collecting requirements\nModule 3 \u2013 Infrastructure Planning: Index Design\n\n\n- Design and size indexes\n- Estimate storage requirements\n- Identify relevant apps\n\nModule 4 \u2013 Infrastructure Planning: Resource Planning\n\n\n- List sizing factors for servers\n- Describe how reference hardware is used to scale deployments\n- Identify the impact of clustering for index replication and for search heads\nModule 5- Clustering Overview\n\n\n- Describe the different clustering capabilities\n- Introduce the concepts of indexer and search head clustering\nModule 6 - Forwarder and Deployment Best Practices\n\n\n- Review types of forwarders\n- Describe how to manage forwarder installation\n- Review configuration management for all Splunk components, using Splunk deployment tools\n- Provide best practices for a Splunk deployment\nModule 7 - Integration \n\n\n- Describe integration methods\n- Identify common integration points\nModule  8 \u2013 Performance Monitoring and Tuning\n\n\n- Use the Monitoring Console to track the performance of your test environment\n- List options to fine tune performance for production environment\nModule 9 \u2013 Use Cases\n\n\n- Provide example architecture topologies\n- Discuss different architecture options based on use case","summary_plain":"This series consists of three modules totaling 36 hours of content and leads to the Splunk Enterprise Certified Architect certification.\n\n\n\nThe series consists of the following courses:\n\n\n\n\n- Troubleshooting Splunk Enterprise (TSE)\n- Splunk Enterprise Cluster Administration (SCLA)\n- Architecting Splunk Enterprise Deployments (ASED)","skill_level":"Intermediate","version":"1.0","duration":{"unit":"d","value":5,"formatted":"5 jours"},"pricelist":{"List Price":{"SI":{"country":"SI","currency":"EUR","taxrate":20,"price":4000},"GR":{"country":"GR","currency":"EUR","taxrate":null,"price":4000},"MK":{"country":"MK","currency":"EUR","taxrate":null,"price":4000},"HU":{"country":"HU","currency":"EUR","taxrate":20,"price":4000},"GB":{"country":"GB","currency":"GBP","taxrate":20,"price":3335},"FR":{"country":"FR","currency":"EUR","taxrate":19.6,"price":4000},"PL":{"country":"PL","currency":"USD","taxrate":23,"price":4000},"DE":{"country":"DE","currency":"EUR","taxrate":19,"price":4000},"NL":{"country":"NL","currency":"EUR","taxrate":21,"price":4000},"SG":{"country":"SG","currency":"USD","taxrate":8,"price":4000},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":4400}}},"lastchanged":"2025-10-14T10:20:46+02:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-course-schedule\/29607","source_lang":"fr","source":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-course\/splunk-arch-ft"}}