Mô tả

I am going to get you to the point to be an Expert on Splunk Technology so you are not going to only pass this exam, but also to help you become a subject matter expert in the world of SIEM.  

This is a new Splunk course uploaded for the first time as of November 18 2022 with the latest updates from Splunk!


This course is designed specifically for you, and I have divided it into milestones, each milestone starts with a concept on a specific Splunk topic/functionality so you can grasp it and then we end the section with a demo lab. At the end of this course, I walk you through a life scenario where we will simulate different use cases from a customer's perspective and we start building our lab from the design aspect, then we move to the deployment phase and finally we implement those use cases by deploying different apps as well as creation of custom app which are part of the data onboarding process.


The best hands-on labs course for learning Splunk and crack the Splunk enterprise Certified Admin Course, the leader in real-time monitoring, log management, and SIEM (security information and event management).


Your instructor is Saif Al-Shoker, a Splunk Certified core Consultant and Architect with over 10 years of experience in the security domain, 5 years splunking and hold two master degrees.


Don't buy poor-quality courses! This course is a  high quality that I will take you step by step to successfully deploy Splunk in a distributed architecture design, through engaging video tutorials and teach you everything you need to know to be a successful Splunk Administrator, please check the content.


Look no further ! This is the most comprehensive full LAB implementation —course that covers the latest versions of Splunk Enterprise


In this class, we will cover everything on the exam blueprint. We will provide you with the tools you need to pass the exam and get certified with Tons of Labs!


Whether you've inherited a Splunk environment, are building one from scratch, or are simply curious about Splunk, this course was designed specifically for you!

We'll cover it all...

I remember my first time when I started to learn Splunk, I didn’t know where to start and with all the information out there makes it even harder to grasp, so today I am putting my self in your shoes to help you conquer this complexity .so I have designed this course specially for you


Bạn sẽ học được gì

easily pass the Splunk Enterprise 9.x Certified Admin exam!

Master all aspects of Splunk configuration via CLI and the Web with practical Labs

Set up a working Splunk environment from scratch in a distributed architecture design ( a complete Practical Lab )

understand and implement data collection methods with Splunk ( monitoring inputs, scripted inputs, network inputs, HTTP event collector )

understand and implement data onboarding with Splunk

understand and implement Splunk Forwarding methodology in real life

understand and deploy Splunk forwarder management

understand Splunk indexing, retention policy and bucket life cycle

Explore Splunk apps and the thriving Splunkbase community

Users, roles, and authentication

How to troubleshoot a Splunk Environment

Yêu cầu

  • Computer with Internet Connection
  • basic Linux knowledge
  • Understand how to install software on Linux and Windows

Nội dung khoá học

14 sections

Introduction

3 lectures
Getting started with Splunk
03:27
What does Splunk do?
04:03
Splunk Components at a glance and Architecture Overview
05:12

Splunk Components more in Depth

1 lectures
Splunk Components in Depth
14:40

Splunk Installation and best practices

12 lectures
Splunk Deployment Prerequisites
11:45
Document - Splunk download and Splunk installation steps for Linux with tgz file
00:42
Document - Network settings and recourses
00:32
Document - Splunk System Requirements recourses
00:03
LAB: Deploy Splunk on a Linux Machine
11:25
LAB: Spunk Best Practices - Disable Transparent Huge Pages on Linux
05:05
Document - Disable THP on Linux machine
00:46
LAB: Spunk Best Practices - Increase ulimit on Linux
01:24
LAB: Spunk Best Practices - Configure Splunk Enterprise to start at boot time
02:59
Document - configure Ulimit and recourses
00:23
LAB: Spunk Best Practices - Post Installation Health Check
04:16
Deploy Splunk on a Windows Machine
02:42

Splunk Apps and Add-Ons

2 lectures
Introduction to Splunk Apps / Add-ons and deploying your first App via the web
13:08
Deploying Splunk Apps / Add-ons via the CLI
05:00

Splunk Configuration Files precedence and Directory Structure

3 lectures
Demo: Configuration Files structure
10:55
Understand Splunk configuration Layering ( Global Context vs App/User Context )
09:49
Document - Splunk Configuration file Resources
00:03

Splunk Indexes

7 lectures
Introduction to Splunk Indexes
07:21
Demo: Splunk Index's Structure
10:02
Splunk Index - Buckets Life Cycle and Retention Policy
05:11
LAB: Splunk Indexes - Add Splunk Index via the web and CLI
19:23
Splunk Indexes: Backup and deletion
10:06
The Fishbucket Concept in Splunk
06:27
Document - Fishbucket recourses
00:03

Splunk User Management

2 lectures
Describe Splunk User roles and create Custom ones
09:16
LAB: Integrate Splunk with LDAP
15:27

Hands-On Labs: Deploy and configure Splunk platform in a distributed environment

6 lectures
LAB: Discuss and deploy the Universal Forwarder on Linux
06:46
LAB: Configure the UF for monitoring input and forward the logs to the Indexer
18:15
LAB: Discuss and configure the Indexer for log receiving
16:16
LAB: Discuss and deploy the Universal Forwarder on a windows machine
09:55
LAB: configure the Indexer and deploy Windows App on the UF and the Indexer
18:59
LAB: Discuss and deploy the Search Head as part of the distributed Architecture
09:42

data collection methodology

3 lectures
discussion on Data Collection Methods in a distributed environment
07:29
Discussion on Metadata Fields and data flow (continuation )
08:54
Why Sourcetype Matters?
11:10

Forwarder Deployment Topologies in a Distributed Architecture Design

4 lectures
Data consolidation and Load balancing topology (introduction to Event breaking)
17:56
Discuss forwarding the data based on Routing and filtering
01:53
Forwarding the data to the Indexing tier via Intermediate Forwarders
02:51
Discussion on Why using Universal Forwarders over the Heavy Forwarders?
03:15

LAB: Introduction to the Deployment Server and Lab Implementation

2 lectures
Introduction to the Deployment Server, Deployment Clients and the Server Class
08:57
LAB: Deploy the Deployment Server and the Deployment Clients
24:22

data inputs

8 lectures
Introduction to data inputs ( data collection methodology )
06:49
LAB: Discuss and deploy the Universal Forwarder and set the monitoring inputs
13:44
LAB: Configure the UF to monitor specific files
05:47
LAB: Introduction to file pathname wildcards & host_regex & host_segment concept
14:59
LAB: Introduction to using whitelist to include files ( monitor inputs )
07:54
LAB: Configure the Firewall to forward the logs to the UF ( Network Input )
14:56
LAB: Discuss and implement Scripted Inputs
07:00
LAB: Discussion and Implementation of the HTTP Event Collector
15:56

LAB: Deploy Splunk Enterprise (Complete LAB Implantation )

8 lectures
Lab setup Overview
05:16
LAB: Introduction to AWS and Deploy Splunk Instances on AWS
11:37
Splunk Deployment Walkthrough in a distributed Environment
06:29
LAB: Deploy Splunk Components and forward the logs to the indexing Tier
31:49
LAB: Deploy UFs, IFs (Linux), UF (Windows) & join them to the Deployment Server
16:45
LAB: Deploy Base Apps to the UFs, IFs & UF on Windows via the Deployment Server
21:25
LAB: Implement different use cases on the Universal Forwarders
36:07
LAB: Deploy the heavy forwarder via the DS and forward Fortigate Firewall Logs
17:40

LAB: Data Onboarding Overview ( LAB continuation )

7 lectures
LAB: Data Onboarding Overview and working with props.conf and transforms.conf
06:01
Document - Splunk Data Onboarding Recourses
00:01
Document - Learn Regular Expressions - Recourses
00:03
LAB: Use Data Preview to validate event creation during the parsing phase
11:55
LAB: Data onboarding - field extractions with props.conf
07:19
LAB: Manipulating the Data using SEDCMD in props.conf
10:48
LAB: Manipulating Raw Data and how to mask the data using props and transforms
11:36

Đánh giá của học viên

Chưa có đánh giá
Course Rating
5
0%
4
0%
3
0%
2
0%
1
0%

Bình luận khách hàng

Viết Bình Luận

Bạn đánh giá khoá học này thế nào?

image

Đăng ký get khoá học Udemy - Unica - Gitiho giá chỉ 50k!

Get khoá học giá rẻ ngay trước khi bị fix.