<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26427" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/splunk-sci" lastchanged="2025-07-29T12:18:12+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Services Core Implementation</title><productcode>SCI</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SCI</fullproductcode><version>1.0</version><objective>&lt;p&gt;&lt;strong&gt;Topic 1 &amp;ndash; Deploying Splunk&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Introduce the Splunk Validated Architectures&lt;/li&gt;&lt;li&gt;Review how Splunk can grow from a standalone environment to a distributed environment with indexer and search head clustering&lt;/li&gt;&lt;li&gt;Explain High Availability and Disaster Recovery&lt;/li&gt;&lt;li&gt;Discuss migrating Splunk from on-premises to the Cloud&lt;/li&gt;&lt;li&gt;Lab 0: Grade Me&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 2 &amp;ndash; Monitoring Console&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discuss the best instance to configure as the Monitoring Console&lt;/li&gt;&lt;li&gt;Configure the MC for a single or distributed environment&lt;/li&gt;&lt;li&gt;Examine how the MC uses the server roles and groups assigned to instances&lt;/li&gt;&lt;li&gt;Discuss health checks and how they are run&lt;/li&gt;&lt;li&gt;Lab 1 - Discovery&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 3 &amp;ndash; Configuration Management&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define deployment apps&lt;/li&gt;&lt;li&gt;Provide overview of Deployment Server&lt;/li&gt;&lt;li&gt;Describe deployment system configuration&lt;/li&gt;&lt;li&gt;Discuss how to manage Deployment Server at scale&lt;/li&gt;&lt;li&gt;Lab 5: Scale DS&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 4 &amp;ndash; Access &amp;amp; Roles&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discuss how to manage Deployment Server at scale&lt;/li&gt;&lt;li&gt;Identify authentication methods&lt;/li&gt;&lt;li&gt;Describe LDAP concepts and configuration&lt;/li&gt;&lt;li&gt;Discuss SAML and SSO options&lt;/li&gt;&lt;li&gt;Define roles and how they are used to protect data&lt;/li&gt;&lt;li&gt;Lab 2: LDAP Integration&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 5 &amp;ndash; Data Collection&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Examine Splunk to Splunk (S2S) communication and the different ways data is sent from forwarder to indexer&lt;/li&gt;&lt;li&gt;Describe the types and configuration of data inputs&lt;/li&gt;&lt;li&gt;Discuss ways to troubleshoot data inputs&lt;/li&gt;&lt;li&gt;Lab 3: Triage broken forwarder&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 6 &amp;ndash; Indexing&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review indexing artifacts and locations&lt;/li&gt;&lt;li&gt;Discuss event processing and data pipelines&lt;/li&gt;&lt;li&gt;Understand the underlying text parsing and indexing process&lt;/li&gt;&lt;li&gt;Examine data retention controls&lt;/li&gt;&lt;li&gt;Lab 4: Triage indexing issue&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 7 &amp;ndash; Search&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Examine the inter-workings of a search&lt;/li&gt;&lt;li&gt;Discuss how to use search job inspection&lt;/li&gt;&lt;li&gt;Look at the different search types and how to maximize search efficiency&lt;/li&gt;&lt;li&gt;Review sub-searches and how they work&lt;/li&gt;&lt;li&gt;Examine some example searches and how to make them more efficient&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 8 &amp;ndash; Index Clustering&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide an architecture overview&lt;/li&gt;&lt;li&gt;Describe deployment and component configuration&lt;/li&gt;&lt;li&gt;Review upgrade strategy&lt;/li&gt;&lt;li&gt;Discuss data buckets and lifecycle&lt;/li&gt;&lt;li&gt;Examine failure modes and recovery processes&lt;/li&gt;&lt;li&gt;Introduce multi-site clustering&lt;/li&gt;&lt;li&gt;Understand migration procedures&lt;/li&gt;&lt;li&gt;Lab 6: Upgrade Index Cluster&lt;/li&gt;&lt;li&gt;Lab 7: Expand Cluster &amp;amp; Migrate Indexer data&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Topic 9 &amp;ndash; Search Head Clustering&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provide overview of Search Head clustering&lt;/li&gt;&lt;li&gt;Explain how to manage and deploy a cluster&lt;/li&gt;&lt;li&gt;Describe content management using the Deployer&lt;/li&gt;&lt;li&gt;Review the role of cluster members and the Captain&lt;/li&gt;&lt;li&gt;Lab 8 &amp;ndash; Install SHC&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appendix A &amp;ndash; REST API&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define the Splunk REST API&lt;/li&gt;&lt;li&gt;Discuss requests, endpoints, and namespaces&lt;/li&gt;&lt;li&gt;Examine tools and methods for using the API&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;ul&gt;
&lt;li&gt;Splunk Certified Architect +&lt;/li&gt;&lt;/ul&gt;</essentials><contents>&lt;ul&gt;
&lt;li&gt;Splunk architecture&lt;/li&gt;&lt;li&gt;Monitoring Console&lt;/li&gt;&lt;li&gt;Deployment Server&lt;/li&gt;&lt;li&gt;LDAP integration&lt;/li&gt;&lt;li&gt;Collecting and forwarding data&lt;/li&gt;&lt;li&gt;Indexing and Searching&lt;/li&gt;&lt;li&gt;Clustering indexers&lt;/li&gt;&lt;li&gt;Clustering Search Heads&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>Topic 1 – Deploying Splunk



- Introduce the Splunk Validated Architectures
- Review how Splunk can grow from a standalone environment to a distributed environment with indexer and search head clustering
- Explain High Availability and Disaster Recovery
- Discuss migrating Splunk from on-premises to the Cloud
- Lab 0: Grade Me

Topic 2 – Monitoring Console



- Discuss the best instance to configure as the Monitoring Console
- Configure the MC for a single or distributed environment
- Examine how the MC uses the server roles and groups assigned to instances
- Discuss health checks and how they are run
- Lab 1 - Discovery

Topic 3 – Configuration Management



- Define deployment apps
- Provide overview of Deployment Server
- Describe deployment system configuration
- Discuss how to manage Deployment Server at scale
- Lab 5: Scale DS

Topic 4 – Access &amp; Roles



- Discuss how to manage Deployment Server at scale
- Identify authentication methods
- Describe LDAP concepts and configuration
- Discuss SAML and SSO options
- Define roles and how they are used to protect data
- Lab 2: LDAP Integration

Topic 5 – Data Collection



- Examine Splunk to Splunk (S2S) communication and the different ways data is sent from forwarder to indexer
- Describe the types and configuration of data inputs
- Discuss ways to troubleshoot data inputs
- Lab 3: Triage broken forwarder

Topic 6 – Indexing



- Review indexing artifacts and locations
- Discuss event processing and data pipelines
- Understand the underlying text parsing and indexing process
- Examine data retention controls
- Lab 4: Triage indexing issue

Topic 7 – Search



- Examine the inter-workings of a search
- Discuss how to use search job inspection
- Look at the different search types and how to maximize search efficiency
- Review sub-searches and how they work
- Examine some example searches and how to make them more efficient

Topic 8 – Index Clustering



- Provide an architecture overview
- Describe deployment and component configuration
- Review upgrade strategy
- Discuss data buckets and lifecycle
- Examine failure modes and recovery processes
- Introduce multi-site clustering
- Understand migration procedures
- Lab 6: Upgrade Index Cluster
- Lab 7: Expand Cluster &amp; Migrate Indexer data

Topic 9 – Search Head Clustering



- Provide overview of Search Head clustering
- Explain how to manage and deploy a cluster
- Describe content management using the Deployer
- Review the role of cluster members and the Captain
- Lab 8 – Install SHC

Appendix A – REST API



- Define the Splunk REST API
- Discuss requests, endpoints, and namespaces
- Examine tools and methods for using the API</objective_plain><essentials_plain>- Splunk Certified Architect +</essentials_plain><contents_plain>- Splunk architecture
- Monitoring Console
- Deployment Server
- LDAP integration
- Collecting and forwarding data
- Indexing and Searching
- Clustering indexers
- Clustering Search Heads</contents_plain><duration unit="d" days="5">5 jours</duration><pricelist><price country="DE" currency="EUR">4000.00</price><price country="AT" currency="EUR">4000.00</price><price country="SE" currency="EUR">4000.00</price><price country="GR" currency="EUR">4000.00</price><price country="MK" currency="EUR">4000.00</price><price country="HU" currency="EUR">4000.00</price><price country="PL" currency="USD">4000.00</price><price country="CH" currency="CHF">4000.00</price></pricelist><miles><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">400.00</milesvalue></miles></course>