<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="29844" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/splunk-se-fs" lastchanged="2026-02-16T21:26:10+01:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Splunk Search Expert Fast Start</title><productcode>SE-FS</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SE-FS</fullproductcode><version>10</version><objective>&lt;p&gt;At the end of the course, you should be able to :
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Search with Time&lt;/li&gt;&lt;li&gt;Format Time&lt;/li&gt;&lt;li&gt;Compare Index Time versus Search Time&lt;/li&gt;&lt;li&gt;Use Time Commands&lt;/li&gt;&lt;li&gt;Work with Time Zones&lt;/li&gt;&lt;li&gt;Understand what is Data Series&lt;/li&gt;&lt;li&gt;Transform Data&lt;/li&gt;&lt;li&gt;Manipulate Data with eval&lt;/li&gt;&lt;li&gt;Format Data&lt;/li&gt;&lt;li&gt;Use eval to Compare&lt;/li&gt;&lt;li&gt;Filter with where&lt;/li&gt;&lt;li&gt;Manipulate Output&lt;/li&gt;&lt;li&gt;Modify Result Sets&lt;/li&gt;&lt;li&gt;Manage Missing Data&lt;/li&gt;&lt;li&gt;Modify Field Values&lt;/li&gt;&lt;li&gt;Normalize with eval&lt;/li&gt;&lt;li&gt;Use Lookup Commands&lt;/li&gt;&lt;li&gt;Add a Subsearch&lt;/li&gt;&lt;li&gt;Use the return Command&lt;/li&gt;&lt;li&gt;Calculate Co-Occurrence Between Fields&lt;/li&gt;&lt;li&gt;Analyze Multiple Datasets&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful, students should have a solid understanding of the following:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Works&lt;/li&gt;&lt;li&gt;Creating Search queries&lt;/li&gt;&lt;li&gt;Knowledge objects (specifically reports, lookups, and fields)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;OR have taken the following:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Foundation Fast Start OR&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;attentionbbcode&quot; title=&quot;inactive or disabled course: SP-WIS&quot;&gt;!&lt;/span&gt;What is Splunk? &lt;span class=&quot;fl-prod-pcode&quot;&gt;(WIS)&lt;/span&gt;, &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/product/splunk-its&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Intro to Splunk &lt;span class=&quot;fl-prod-pcode&quot;&gt;(ITS)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; and &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><contents>&lt;h5&gt;Topic 1 &amp;ndash; Working with Time&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Searching with Time&lt;/li&gt;&lt;li&gt;Formatting Time&lt;/li&gt;&lt;li&gt;Comparing index Time versus Search Time&lt;/li&gt;&lt;li&gt;Using Time Commands&lt;/li&gt;&lt;li&gt;Working with Time Zones&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 2 &amp;ndash; Statistical Processing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What is a Data Series?&lt;/li&gt;&lt;li&gt;Transforming Data&lt;/li&gt;&lt;li&gt;Manipulating Data with eval&lt;/li&gt;&lt;li&gt;Formatting Data&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 3 &amp;ndash; Comparing Values&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using eval to Compare&lt;/li&gt;&lt;li&gt;Filtering with where&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 4 &amp;ndash; Result Modification&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Manipulating Output&lt;/li&gt;&lt;li&gt;Modifying REsults Sets&lt;/li&gt;&lt;li&gt;Managing Missing Data&lt;/li&gt;&lt;li&gt;Modifying Field Values&lt;/li&gt;&lt;li&gt;Normalizing with eval&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 5 &amp;ndash; Leveraging Lookups and Subsearches&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using Lookup Commands&lt;/li&gt;&lt;li&gt;Adding a Subsearch&lt;/li&gt;&lt;li&gt;Using the return Command&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 6 - Correlation Analysis&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Caclulate Co-Occurance Between Fields&lt;/li&gt;&lt;li&gt;Analyze Multiple Datasets&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Topic 1 &amp;ndash; Working with Time&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Searching with Time&lt;/li&gt;&lt;li&gt;Formatting Time&lt;/li&gt;&lt;li&gt;Comparing index Time versus Search Time&lt;/li&gt;&lt;li&gt;Using Time Commands&lt;/li&gt;&lt;li&gt;Working with Time Zones&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 2 &amp;ndash; Statistical Processing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What is a Data Series?&lt;/li&gt;&lt;li&gt;Transforming Data&lt;/li&gt;&lt;li&gt;Manipulating Data with eval&lt;/li&gt;&lt;li&gt;Formatting Data&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 3 &amp;ndash; Comparing Values&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using eval to Compare&lt;/li&gt;&lt;li&gt;Filtering with where&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 4 &amp;ndash; Result Modification&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Manipulating Output&lt;/li&gt;&lt;li&gt;Modifying REsults Sets&lt;/li&gt;&lt;li&gt;Managing Missing Data&lt;/li&gt;&lt;li&gt;Modifying Field Values&lt;/li&gt;&lt;li&gt;Normalizing with eval&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 5 &amp;ndash; Leveraging Lookups and Subsearches&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using Lookup Commands&lt;/li&gt;&lt;li&gt;Adding a Subsearch&lt;/li&gt;&lt;li&gt;Using the return Command&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 6 - Correlation Analysis&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Caclulate Co-Occurance Between Fields&lt;/li&gt;&lt;li&gt;Analyze Multiple Datasets&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>At the end of the course, you should be able to :



- Search with Time
- Format Time
- Compare Index Time versus Search Time
- Use Time Commands
- Work with Time Zones
- Understand what is Data Series
- Transform Data
- Manipulate Data with eval
- Format Data
- Use eval to Compare
- Filter with where
- Manipulate Output
- Modify Result Sets
- Manage Missing Data
- Modify Field Values
- Normalize with eval
- Use Lookup Commands
- Add a Subsearch
- Use the return Command
- Calculate Co-Occurrence Between Fields
- Analyze Multiple Datasets</objective_plain><essentials_plain>To be successful, students should have a solid understanding of the following:



- How Splunk Works
- Creating Search queries
- Knowledge objects (specifically reports, lookups, and fields)
OR have taken the following:



- Foundation Fast Start OR
- What is Splunk? (WIS), Intro to Splunk (ITS) and Using Fields (SUF)</essentials_plain><contents_plain>Topic 1 – Working with Time


- Searching with Time
- Formatting Time
- Comparing index Time versus Search Time
- Using Time Commands
- Working with Time Zones
Topic 2 – Statistical Processing


- What is a Data Series?
- Transforming Data
- Manipulating Data with eval
- Formatting Data
Topic 3 – Comparing Values


- Using eval to Compare
- Filtering with where
Topic 4 – Result Modification


- Manipulating Output
- Modifying REsults Sets
- Managing Missing Data
- Modifying Field Values
- Normalizing with eval
Topic 5 – Leveraging Lookups and Subsearches


- Using Lookup Commands
- Adding a Subsearch
- Using the return Command
Topic 6 - Correlation Analysis


- Caclulate Co-Occurance Between Fields
- Analyze Multiple Datasets</contents_plain><outline_plain>Topic 1 – Working with Time


- Searching with Time
- Formatting Time
- Comparing index Time versus Search Time
- Using Time Commands
- Working with Time Zones
Topic 2 – Statistical Processing


- What is a Data Series?
- Transforming Data
- Manipulating Data with eval
- Formatting Data
Topic 3 – Comparing Values


- Using eval to Compare
- Filtering with where
Topic 4 – Result Modification


- Manipulating Output
- Modifying REsults Sets
- Managing Missing Data
- Modifying Field Values
- Normalizing with eval
Topic 5 – Leveraging Lookups and Subsearches


- Using Lookup Commands
- Adding a Subsearch
- Using the return Command
Topic 6 - Correlation Analysis


- Caclulate Co-Occurance Between Fields
- Analyze Multiple Datasets</outline_plain><duration unit="d" days="3">3 jours</duration><pricelist><price country="SI" currency="EUR">3000.00</price><price country="US" currency="USD">3000.00</price><price country="GR" currency="EUR">3000.00</price><price country="MK" currency="EUR">3000.00</price><price country="HU" currency="EUR">3000.00</price><price country="GB" currency="GBP">2500.00</price><price country="AT" currency="EUR">3000.00</price><price country="FR" currency="EUR">3000.00</price><price country="PL" currency="USD">3000.00</price><price country="DE" currency="EUR">3000.00</price><price country="SE" currency="EUR">3000.00</price><price country="IT" currency="USD">3000.00</price><price country="NL" currency="EUR">3000.00</price><price country="CA" currency="CAD">4140.00</price><price country="CH" currency="CHF">3300.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="FR" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue></miles></course>