<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="29844" language="de" source="https://portal.flane.ch/swisscom/xml-course/splunk-se-fs" lastchanged="2026-02-16T21:26:10+01:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Splunk Search Expert Fast Start</title><productcode>SE-FS</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SE-FS</fullproductcode><version>10</version><essentials>&lt;p&gt;To be successful, students should have a solid understanding of the following:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk Works&lt;/li&gt;&lt;li&gt;Creating Search queries&lt;/li&gt;&lt;li&gt;Knowledge objects (specifically reports, lookups, and fields)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;OR have taken the following:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Foundation Fast Start OR&lt;/li&gt;&lt;li&gt;What is Splunk? (Retired), Intro to Splunk (ITS) and [Using Fields (SUF)&lt;/li&gt;&lt;/ul&gt;</essentials><contents>&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-wwt&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Working with Time &lt;span class=&quot;fl-prod-pcode&quot;&gt;(WWT)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-ssp&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Statistical Processing &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SSP)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-scv&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Comparing Values &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCV)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-srm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Result Modification &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SRM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-lls&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Leveraging Lookups and Subsearches &lt;span class=&quot;fl-prod-pcode&quot;&gt;(LLS)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-sclas&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Correlation Analysis &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCLAS)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Topic 1 &amp;ndash; Working with Time&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Searching with Time&lt;/li&gt;&lt;li&gt;Formatting Time&lt;/li&gt;&lt;li&gt;Comparing index Time versus Search Time&lt;/li&gt;&lt;li&gt;Using Time Commands&lt;/li&gt;&lt;li&gt;Working with Time Zones&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 2 &amp;ndash; Statistical Processing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What is a Data Series?&lt;/li&gt;&lt;li&gt;Transforming Data&lt;/li&gt;&lt;li&gt;Manipulating Data with eval&lt;/li&gt;&lt;li&gt;Formatting Data&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 3 &amp;ndash; Comparing Values&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using eval to Compare&lt;/li&gt;&lt;li&gt;Filtering with where&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 4 &amp;ndash; Result Modification&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Manipulating Output&lt;/li&gt;&lt;li&gt;Modifying REsults Sets&lt;/li&gt;&lt;li&gt;Managing Missing Data&lt;/li&gt;&lt;li&gt;Modifying Field Values&lt;/li&gt;&lt;li&gt;Normalizing with eval&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 5 &amp;ndash; Leveraging Lookups and Subsearches&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Using Lookup Commands&lt;/li&gt;&lt;li&gt;Adding a Subsearch&lt;/li&gt;&lt;li&gt;Using the return Command&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 6 - Correlation Analysis&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Caclulate Co-Occurance Between Fields&lt;/li&gt;&lt;li&gt;Analyze Multiple Datasets&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students should have a solid understanding of the following:



- How Splunk Works
- Creating Search queries
- Knowledge objects (specifically reports, lookups, and fields)
OR have taken the following:



- Foundation Fast Start OR
- What is Splunk? (Retired), Intro to Splunk (ITS) and [Using Fields (SUF)</essentials_plain><contents_plain>- Working with Time (WWT)
- Statistical Processing (SSP)
- Comparing Values (SCV)
- Result Modification (SRM)
- Leveraging Lookups and Subsearches (LLS)
- Correlation Analysis (SCLAS)</contents_plain><outline_plain>Topic 1 – Working with Time


- Searching with Time
- Formatting Time
- Comparing index Time versus Search Time
- Using Time Commands
- Working with Time Zones
Topic 2 – Statistical Processing


- What is a Data Series?
- Transforming Data
- Manipulating Data with eval
- Formatting Data
Topic 3 – Comparing Values


- Using eval to Compare
- Filtering with where
Topic 4 – Result Modification


- Manipulating Output
- Modifying REsults Sets
- Managing Missing Data
- Modifying Field Values
- Normalizing with eval
Topic 5 – Leveraging Lookups and Subsearches


- Using Lookup Commands
- Adding a Subsearch
- Using the return Command
Topic 6 - Correlation Analysis


- Caclulate Co-Occurance Between Fields
- Analyze Multiple Datasets</outline_plain><duration unit="d" days="3">3 Tage</duration><pricelist><price country="SI" currency="EUR">3000.00</price><price country="US" currency="USD">3000.00</price><price country="GR" currency="EUR">3000.00</price><price country="MK" currency="EUR">3000.00</price><price country="HU" currency="EUR">3000.00</price><price country="GB" currency="GBP">2500.00</price><price country="AT" currency="EUR">3000.00</price><price country="FR" currency="EUR">3000.00</price><price country="PL" currency="USD">3000.00</price><price country="DE" currency="EUR">3000.00</price><price country="SE" currency="EUR">3000.00</price><price country="IT" currency="USD">3000.00</price><price country="NL" currency="EUR">3000.00</price><price country="CA" currency="CAD">4140.00</price><price country="CH" currency="CHF">3300.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="FR" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">300.00</milesvalue></miles></course>