<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="29607" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/splunk-arch-ft" lastchanged="2025-10-14T10:20:46+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Splunk Enterprise Architect Fast Start</title><productcode>ARCH-FT</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-ARCH-FT</fullproductcode><version>1.0</version><objective>&lt;p&gt;At the end of this course, you should be able to :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand Splunk Troubleshooting Methods and Tools&lt;/li&gt;&lt;li&gt;Index Problems&lt;/li&gt;&lt;li&gt;Input Configuration Problems&lt;/li&gt;&lt;li&gt;Understand Deployment Problems&lt;/li&gt;&lt;li&gt;Understand License, Upgrade, and User Management Problems&lt;/li&gt;&lt;li&gt;Understand Search Management Problems&lt;/li&gt;&lt;li&gt;User Search Problems&lt;/li&gt;&lt;li&gt;Understand the Splunk Support Model and its resources&lt;/li&gt;&lt;li&gt;Identify the best practices for troubleshooting Splunk Enterprise&lt;/li&gt;&lt;li&gt;List ways to gather useful Splunk diagnostic information&lt;/li&gt;&lt;li&gt;Use Splunk diagnostic tools&lt;/li&gt;&lt;li&gt;Identify common Splunk technical issues and solve them&lt;/li&gt;&lt;li&gt;Understand Requirements definition&lt;/li&gt;&lt;li&gt;Understand Index and resource planning&lt;/li&gt;&lt;li&gt;Understand Cluster&lt;/li&gt;&lt;li&gt;Understand Forwarder and Deployment&lt;/li&gt;&lt;li&gt;Integration&lt;/li&gt;&lt;li&gt;Understand Performance Monitoring and Tuning&lt;/li&gt;&lt;li&gt;Understand Large-scale Splunk Deployment&lt;/li&gt;&lt;li&gt;Understand Single-site Indexer Cluster&lt;/li&gt;&lt;li&gt;Understand Indexer Cluster Management and Administration&lt;/li&gt;&lt;li&gt;Understand Forwarder Configuration&lt;/li&gt;&lt;li&gt;Understand Search Head Cluster&lt;/li&gt;&lt;li&gt;Understand Search Head Cluster Management and Administration&lt;/li&gt;&lt;li&gt;Understand KV Store Collection and Lookup Management&lt;/li&gt;&lt;li&gt;Understand SmartStore Implementation&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;Splunk Core Certified Power User AND Splunk Enterprise Certified Admin.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Hard pre-req:&lt;/strong&gt; The three ILTs in this path PLUS the Splunk Enterprise Practical Lab.&lt;/p&gt;</essentials><audience>&lt;p&gt;Splunk administrators
Eexperienced Splunk Enterprise administrator who is new to Splunk Clusters&lt;/p&gt;</audience><contents>&lt;h4&gt;Troubleshooting Splunk Enterprise&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Splunk Troubleshooting Methods and Tools&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Splunk Troubleshooting Approach&lt;/li&gt;&lt;li&gt;List Splunk Diagnostic Resources and Tools&lt;/li&gt;&lt;li&gt;Create and Splunk a Diag&lt;/li&gt;&lt;li&gt;Use RapidDiag&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Indexing Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discover Splunk Deployment Topology and its Server Roles&lt;/li&gt;&lt;li&gt;Identify Where to Check the Index-Time Pipeline Status&lt;/li&gt;&lt;li&gt;Use the metrics.log to Clarify the Index-Time Problem&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Input Configuration Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Data Input Issues&lt;/li&gt;&lt;li&gt;Troubleshooting Inputs with the Monitoring Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Deployment and Forwarder Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployment Server Issues&lt;/li&gt;&lt;li&gt;Forwarding and Receiving Issues&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; License, Upgrade, and User Management Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Installation Issues&lt;/li&gt;&lt;li&gt;Upgrade Considerations&lt;/li&gt;&lt;li&gt;Splunk Licensing Issues&lt;/li&gt;&lt;li&gt;Splunk Roles and User Management Issues&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Search Head Management Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Troubleshoot Distributed Search Issues&lt;/li&gt;&lt;li&gt;Identify Job Scheduling Problems&lt;/li&gt;&lt;li&gt;Learn to Diagnose Crashing Problems&lt;/li&gt;&lt;li&gt;Describe How to Prioritize Resources for Critical Splunk Processes&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; User Search Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify the Types of Search Problems&lt;/li&gt;&lt;li&gt;Isolate and Troubleshoot Search Problems&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Splunk Enterprise Cluster Administration&lt;/h5&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Splunk Troubleshooting Methods and Tools&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployment Design Factors&lt;/li&gt;&lt;li&gt;How Splunk Enterprise can scale&lt;/li&gt;&lt;li&gt;Splunk License Master&lt;/li&gt;&lt;li&gt;Splunk 9.0 Security&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Single-site Indexer Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Single-Site Indexer Clusters Work&lt;/li&gt;&lt;li&gt;Indexer Cluster Components and Terms&lt;/li&gt;&lt;li&gt;Splunk single-site Indexer Cluster Configuration&lt;/li&gt;&lt;li&gt;Splunk Indexer Cluster Log Channels&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Multisite Indexer Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Multisite Indexer Clusters Work&lt;/li&gt;&lt;li&gt;Multisite Indexer Cluster Terms&lt;/li&gt;&lt;li&gt;Multisite Indexer Cluster Configuration&lt;/li&gt;&lt;li&gt;Optional Multisite Indexer Cluster Configurations&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Indexer Cluster Management and Administration&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Peer Offline and Decommission&lt;/li&gt;&lt;li&gt;Master App Bundles&lt;/li&gt;&lt;li&gt;Indexer Cluster Storage Utilization Options&lt;/li&gt;&lt;li&gt;Site Mapping&lt;/li&gt;&lt;li&gt;Monitoring Console for Indexer Cluster Environment&lt;/li&gt;&lt;li&gt;Cluster Manager Redundancy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Forwarder Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Indexer Discovery&lt;/li&gt;&lt;li&gt;Optional Indexer Discovery Configurations&lt;/li&gt;&lt;li&gt;Volume-Based Forwarder Load Balancing&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Search Head Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Search Head Cluster Architecture&lt;/li&gt;&lt;li&gt;Search Head Cluster Configuration&lt;/li&gt;&lt;li&gt;Captaincy Identification and Cluster Status&lt;/li&gt;&lt;li&gt;Search Head Cluster Settings&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Search Head Cluster Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Search Head Cluster Deployer&lt;/li&gt;&lt;li&gt;Captaincy Transfer&lt;/li&gt;&lt;li&gt;Search Head Member Addition and Decommissioning&lt;/li&gt;&lt;li&gt;Monitoring Console for Search Head Cluster&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; KV Store Collection and Lookup Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;KV Store Collection in Splunk Clusters&lt;/li&gt;&lt;li&gt;KV Store Monitoring with Monitoring Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Introduction to Smart Store&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SmartStore Deployment Use Cases&lt;/li&gt;&lt;li&gt;SmartStore Architecture Overview&lt;/li&gt;&lt;li&gt;Enable SmartStore in Indexer Cluster&lt;/li&gt;&lt;li&gt;Monitor SmartStore Status&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Architecting Splunk Enterprise Deployments&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Introduction&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview of the Splunk deployment planning process and associated tools&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Project Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify critical information about environment, volume, users, and requirements&lt;/li&gt;&lt;li&gt;Review checklists and resources to aid in collecting requirements&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Infrastructure Planning: Index Design&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Design and size indexes&lt;/li&gt;&lt;li&gt;Estimate storage requirements&lt;/li&gt;&lt;li&gt;Identify relevant apps&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Infrastructure Planning: Resource Planning&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List sizing factors for servers&lt;/li&gt;&lt;li&gt;Describe how reference hardware is used to scale deployments&lt;/li&gt;&lt;li&gt;Identify the impact of clustering for index replication and for search heads&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5- Clustering Overview&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the different clustering capabilities&lt;/li&gt;&lt;li&gt;Introduce the concepts of indexer and search head clustering&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 - Forwarder and Deployment Best Practices&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review types of forwarders&lt;/li&gt;&lt;li&gt;Describe how to manage forwarder installation&lt;/li&gt;&lt;li&gt;Review configuration management for all Splunk components, using Splunk deployment tools&lt;/li&gt;&lt;li&gt;Provide best practices for a Splunk deployment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 - Integration &lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe integration methods&lt;/li&gt;&lt;li&gt;Identify common integration points&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module  8 &amp;ndash; Performance Monitoring and Tuning&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use the Monitoring Console to track the performance of your test environment&lt;/li&gt;&lt;li&gt;List options to fine tune performance for production environment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Use Cases&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide example architecture topologies&lt;/li&gt;&lt;li&gt;Discuss different architecture options based on use case&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h4&gt;Troubleshooting Splunk Enterprise&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Splunk Troubleshooting Methods and Tools&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Splunk Troubleshooting Approach&lt;/li&gt;&lt;li&gt;List Splunk Diagnostic Resources and Tools&lt;/li&gt;&lt;li&gt;Create and Splunk a Diag&lt;/li&gt;&lt;li&gt;Use RapidDiag&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Indexing Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discover Splunk Deployment Topology and its Server Roles&lt;/li&gt;&lt;li&gt;Identify Where to Check the Index-Time Pipeline Status&lt;/li&gt;&lt;li&gt;Use the metrics.log to Clarify the Index-Time Problem&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Input Configuration Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Data Input Issues&lt;/li&gt;&lt;li&gt;Troubleshooting Inputs with the Monitoring Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Deployment and Forwarder Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployment Server Issues&lt;/li&gt;&lt;li&gt;Forwarding and Receiving Issues&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; License, Upgrade, and User Management Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Installation Issues&lt;/li&gt;&lt;li&gt;Upgrade Considerations&lt;/li&gt;&lt;li&gt;Splunk Licensing Issues&lt;/li&gt;&lt;li&gt;Splunk Roles and User Management Issues&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Search Head Management Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Troubleshoot Distributed Search Issues&lt;/li&gt;&lt;li&gt;Identify Job Scheduling Problems&lt;/li&gt;&lt;li&gt;Learn to Diagnose Crashing Problems&lt;/li&gt;&lt;li&gt;Describe How to Prioritize Resources for Critical Splunk Processes&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; User Search Problems&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify the Types of Search Problems&lt;/li&gt;&lt;li&gt;Isolate and Troubleshoot Search Problems&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Splunk Enterprise Cluster Administration&lt;/h5&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Splunk Troubleshooting Methods and Tools&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployment Design Factors&lt;/li&gt;&lt;li&gt;How Splunk Enterprise can scale&lt;/li&gt;&lt;li&gt;Splunk License Master&lt;/li&gt;&lt;li&gt;Splunk 9.0 Security&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Single-site Indexer Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Single-Site Indexer Clusters Work&lt;/li&gt;&lt;li&gt;Indexer Cluster Components and Terms&lt;/li&gt;&lt;li&gt;Splunk single-site Indexer Cluster Configuration&lt;/li&gt;&lt;li&gt;Splunk Indexer Cluster Log Channels&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Multisite Indexer Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Multisite Indexer Clusters Work&lt;/li&gt;&lt;li&gt;Multisite Indexer Cluster Terms&lt;/li&gt;&lt;li&gt;Multisite Indexer Cluster Configuration&lt;/li&gt;&lt;li&gt;Optional Multisite Indexer Cluster Configurations&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Indexer Cluster Management and Administration&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Peer Offline and Decommission&lt;/li&gt;&lt;li&gt;Master App Bundles&lt;/li&gt;&lt;li&gt;Indexer Cluster Storage Utilization Options&lt;/li&gt;&lt;li&gt;Site Mapping&lt;/li&gt;&lt;li&gt;Monitoring Console for Indexer Cluster Environment&lt;/li&gt;&lt;li&gt;Cluster Manager Redundancy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Forwarder Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Indexer Discovery&lt;/li&gt;&lt;li&gt;Optional Indexer Discovery Configurations&lt;/li&gt;&lt;li&gt;Volume-Based Forwarder Load Balancing&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Search Head Cluster&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Search Head Cluster Architecture&lt;/li&gt;&lt;li&gt;Search Head Cluster Configuration&lt;/li&gt;&lt;li&gt;Captaincy Identification and Cluster Status&lt;/li&gt;&lt;li&gt;Search Head Cluster Settings&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Search Head Cluster Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Search Head Cluster Deployer&lt;/li&gt;&lt;li&gt;Captaincy Transfer&lt;/li&gt;&lt;li&gt;Search Head Member Addition and Decommissioning&lt;/li&gt;&lt;li&gt;Monitoring Console for Search Head Cluster&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; KV Store Collection and Lookup Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;KV Store Collection in Splunk Clusters&lt;/li&gt;&lt;li&gt;KV Store Monitoring with Monitoring Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Introduction to Smart Store&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SmartStore Deployment Use Cases&lt;/li&gt;&lt;li&gt;SmartStore Architecture Overview&lt;/li&gt;&lt;li&gt;Enable SmartStore in Indexer Cluster&lt;/li&gt;&lt;li&gt;Monitor SmartStore Status&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Architecting Splunk Enterprise Deployments&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Module 1 &amp;ndash; Introduction&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview of the Splunk deployment planning process and associated tools&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2 &amp;ndash; Project Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify critical information about environment, volume, users, and requirements&lt;/li&gt;&lt;li&gt;Review checklists and resources to aid in collecting requirements&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3 &amp;ndash; Infrastructure Planning: Index Design&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Design and size indexes&lt;/li&gt;&lt;li&gt;Estimate storage requirements&lt;/li&gt;&lt;li&gt;Identify relevant apps&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Infrastructure Planning: Resource Planning&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List sizing factors for servers&lt;/li&gt;&lt;li&gt;Describe how reference hardware is used to scale deployments&lt;/li&gt;&lt;li&gt;Identify the impact of clustering for index replication and for search heads&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5- Clustering Overview&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the different clustering capabilities&lt;/li&gt;&lt;li&gt;Introduce the concepts of indexer and search head clustering&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 - Forwarder and Deployment Best Practices&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review types of forwarders&lt;/li&gt;&lt;li&gt;Describe how to manage forwarder installation&lt;/li&gt;&lt;li&gt;Review configuration management for all Splunk components, using Splunk deployment tools&lt;/li&gt;&lt;li&gt;Provide best practices for a Splunk deployment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 - Integration &lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe integration methods&lt;/li&gt;&lt;li&gt;Identify common integration points&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module  8 &amp;ndash; Performance Monitoring and Tuning&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use the Monitoring Console to track the performance of your test environment&lt;/li&gt;&lt;li&gt;List options to fine tune performance for production environment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9 &amp;ndash; Use Cases&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide example architecture topologies&lt;/li&gt;&lt;li&gt;Discuss different architecture options based on use case&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>At the end of this course, you should be able to :


- Understand Splunk Troubleshooting Methods and Tools
- Index Problems
- Input Configuration Problems
- Understand Deployment Problems
- Understand License, Upgrade, and User Management Problems
- Understand Search Management Problems
- User Search Problems
- Understand the Splunk Support Model and its resources
- Identify the best practices for troubleshooting Splunk Enterprise
- List ways to gather useful Splunk diagnostic information
- Use Splunk diagnostic tools
- Identify common Splunk technical issues and solve them
- Understand Requirements definition
- Understand Index and resource planning
- Understand Cluster
- Understand Forwarder and Deployment
- Integration
- Understand Performance Monitoring and Tuning
- Understand Large-scale Splunk Deployment
- Understand Single-site Indexer Cluster
- Understand Indexer Cluster Management and Administration
- Understand Forwarder Configuration
- Understand Search Head Cluster
- Understand Search Head Cluster Management and Administration
- Understand KV Store Collection and Lookup Management
- Understand SmartStore Implementation</objective_plain><essentials_plain>Splunk Core Certified Power User AND Splunk Enterprise Certified Admin.

Hard pre-req: The three ILTs in this path PLUS the Splunk Enterprise Practical Lab.</essentials_plain><audience_plain>Splunk administrators
Eexperienced Splunk Enterprise administrator who is new to Splunk Clusters</audience_plain><contents_plain>Troubleshooting Splunk Enterprise


Module 1 – Splunk Troubleshooting Methods and Tools


- Describe the Splunk Troubleshooting Approach
- List Splunk Diagnostic Resources and Tools
- Create and Splunk a Diag
- Use RapidDiag
Module 2 – Indexing Problems


- Discover Splunk Deployment Topology and its Server Roles
- Identify Where to Check the Index-Time Pipeline Status
- Use the metrics.log to Clarify the Index-Time Problem
Module 3 – Input Configuration Problems


- Data Input Issues
- Troubleshooting Inputs with the Monitoring Console
Module 4 – Deployment and Forwarder Problems


- Deployment Server Issues
- Forwarding and Receiving Issues
Module 5 – License, Upgrade, and User Management Problems


- Installation Issues
- Upgrade Considerations
- Splunk Licensing Issues
- Splunk Roles and User Management Issues
Module 6 – Search Head Management Problems


- Troubleshoot Distributed Search Issues
- Identify Job Scheduling Problems
- Learn to Diagnose Crashing Problems
- Describe How to Prioritize Resources for Critical Splunk Processes
Module 7 – User Search Problems


- Identify the Types of Search Problems
- Isolate and Troubleshoot Search Problems
Splunk Enterprise Cluster Administration


Module 1 – Splunk Troubleshooting Methods and Tools



- Deployment Design Factors
- How Splunk Enterprise can scale
- Splunk License Master
- Splunk 9.0 Security
Module 2 – Single-site Indexer Cluster



- How Splunk Single-Site Indexer Clusters Work
- Indexer Cluster Components and Terms
- Splunk single-site Indexer Cluster Configuration
- Splunk Indexer Cluster Log Channels
Module 3 – Multisite Indexer Cluster



- How Splunk Multisite Indexer Clusters Work
- Multisite Indexer Cluster Terms
- Multisite Indexer Cluster Configuration
- Optional Multisite Indexer Cluster Configurations
Module 4 – Indexer Cluster Management and Administration



- Peer Offline and Decommission
- Master App Bundles
- Indexer Cluster Storage Utilization Options
- Site Mapping
- Monitoring Console for Indexer Cluster Environment
- Cluster Manager Redundancy
Module 5 – Forwarder Management



- Indexer Discovery
- Optional Indexer Discovery Configurations
- Volume-Based Forwarder Load Balancing
Module 6 – Search Head Cluster



- Search Head Cluster Architecture
- Search Head Cluster Configuration
- Captaincy Identification and Cluster Status
- Search Head Cluster Settings
Module 7 – Search Head Cluster Management



- Search Head Cluster Deployer
- Captaincy Transfer
- Search Head Member Addition and Decommissioning
- Monitoring Console for Search Head Cluster
Module 8 – KV Store Collection and Lookup Management



- KV Store Collection in Splunk Clusters
- KV Store Monitoring with Monitoring Console
Module 9 – Introduction to Smart Store



- SmartStore Deployment Use Cases
- SmartStore Architecture Overview
- Enable SmartStore in Indexer Cluster
- Monitor SmartStore Status
Architecting Splunk Enterprise Deployments


Module 1 – Introduction


- Overview of the Splunk deployment planning process and associated tools
Module 2 – Project Requirements


- Identify critical information about environment, volume, users, and requirements
- Review checklists and resources to aid in collecting requirements
Module 3 – Infrastructure Planning: Index Design


- Design and size indexes
- Estimate storage requirements
- Identify relevant apps

Module 4 – Infrastructure Planning: Resource Planning


- List sizing factors for servers
- Describe how reference hardware is used to scale deployments
- Identify the impact of clustering for index replication and for search heads
Module 5- Clustering Overview


- Describe the different clustering capabilities
- Introduce the concepts of indexer and search head clustering
Module 6 - Forwarder and Deployment Best Practices


- Review types of forwarders
- Describe how to manage forwarder installation
- Review configuration management for all Splunk components, using Splunk deployment tools
- Provide best practices for a Splunk deployment
Module 7 - Integration 


- Describe integration methods
- Identify common integration points
Module  8 – Performance Monitoring and Tuning


- Use the Monitoring Console to track the performance of your test environment
- List options to fine tune performance for production environment
Module 9 – Use Cases


- Provide example architecture topologies
- Discuss different architecture options based on use case</contents_plain><outline_plain>Troubleshooting Splunk Enterprise


Module 1 – Splunk Troubleshooting Methods and Tools


- Describe the Splunk Troubleshooting Approach
- List Splunk Diagnostic Resources and Tools
- Create and Splunk a Diag
- Use RapidDiag
Module 2 – Indexing Problems


- Discover Splunk Deployment Topology and its Server Roles
- Identify Where to Check the Index-Time Pipeline Status
- Use the metrics.log to Clarify the Index-Time Problem
Module 3 – Input Configuration Problems


- Data Input Issues
- Troubleshooting Inputs with the Monitoring Console
Module 4 – Deployment and Forwarder Problems


- Deployment Server Issues
- Forwarding and Receiving Issues
Module 5 – License, Upgrade, and User Management Problems


- Installation Issues
- Upgrade Considerations
- Splunk Licensing Issues
- Splunk Roles and User Management Issues
Module 6 – Search Head Management Problems


- Troubleshoot Distributed Search Issues
- Identify Job Scheduling Problems
- Learn to Diagnose Crashing Problems
- Describe How to Prioritize Resources for Critical Splunk Processes
Module 7 – User Search Problems


- Identify the Types of Search Problems
- Isolate and Troubleshoot Search Problems
Splunk Enterprise Cluster Administration


Module 1 – Splunk Troubleshooting Methods and Tools



- Deployment Design Factors
- How Splunk Enterprise can scale
- Splunk License Master
- Splunk 9.0 Security
Module 2 – Single-site Indexer Cluster



- How Splunk Single-Site Indexer Clusters Work
- Indexer Cluster Components and Terms
- Splunk single-site Indexer Cluster Configuration
- Splunk Indexer Cluster Log Channels
Module 3 – Multisite Indexer Cluster



- How Splunk Multisite Indexer Clusters Work
- Multisite Indexer Cluster Terms
- Multisite Indexer Cluster Configuration
- Optional Multisite Indexer Cluster Configurations
Module 4 – Indexer Cluster Management and Administration



- Peer Offline and Decommission
- Master App Bundles
- Indexer Cluster Storage Utilization Options
- Site Mapping
- Monitoring Console for Indexer Cluster Environment
- Cluster Manager Redundancy
Module 5 – Forwarder Management



- Indexer Discovery
- Optional Indexer Discovery Configurations
- Volume-Based Forwarder Load Balancing
Module 6 – Search Head Cluster



- Search Head Cluster Architecture
- Search Head Cluster Configuration
- Captaincy Identification and Cluster Status
- Search Head Cluster Settings
Module 7 – Search Head Cluster Management



- Search Head Cluster Deployer
- Captaincy Transfer
- Search Head Member Addition and Decommissioning
- Monitoring Console for Search Head Cluster
Module 8 – KV Store Collection and Lookup Management



- KV Store Collection in Splunk Clusters
- KV Store Monitoring with Monitoring Console
Module 9 – Introduction to Smart Store



- SmartStore Deployment Use Cases
- SmartStore Architecture Overview
- Enable SmartStore in Indexer Cluster
- Monitor SmartStore Status
Architecting Splunk Enterprise Deployments


Module 1 – Introduction


- Overview of the Splunk deployment planning process and associated tools
Module 2 – Project Requirements


- Identify critical information about environment, volume, users, and requirements
- Review checklists and resources to aid in collecting requirements
Module 3 – Infrastructure Planning: Index Design


- Design and size indexes
- Estimate storage requirements
- Identify relevant apps

Module 4 – Infrastructure Planning: Resource Planning


- List sizing factors for servers
- Describe how reference hardware is used to scale deployments
- Identify the impact of clustering for index replication and for search heads
Module 5- Clustering Overview


- Describe the different clustering capabilities
- Introduce the concepts of indexer and search head clustering
Module 6 - Forwarder and Deployment Best Practices


- Review types of forwarders
- Describe how to manage forwarder installation
- Review configuration management for all Splunk components, using Splunk deployment tools
- Provide best practices for a Splunk deployment
Module 7 - Integration 


- Describe integration methods
- Identify common integration points
Module  8 – Performance Monitoring and Tuning


- Use the Monitoring Console to track the performance of your test environment
- List options to fine tune performance for production environment
Module 9 – Use Cases


- Provide example architecture topologies
- Discuss different architecture options based on use case</outline_plain><duration unit="d" days="5">5 jours</duration><pricelist><price country="SI" currency="EUR">4000.00</price><price country="GR" currency="EUR">4000.00</price><price country="MK" currency="EUR">4000.00</price><price country="HU" currency="EUR">4000.00</price><price country="GB" currency="GBP">3335.00</price><price country="FR" currency="EUR">4000.00</price><price country="PL" currency="USD">4000.00</price><price country="DE" currency="EUR">4000.00</price><price country="NL" currency="EUR">4000.00</price><price country="SG" currency="USD">4000.00</price><price country="CH" currency="CHF">4400.00</price></pricelist><miles><milesvalue country="FR" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue></miles></course>