Splunk® Enterprise Admin: managing and securing data infrastructure
Your Splunk platform must remain usable as volumes and requirements evolve. Connect configuration, architecture and operational monitoring to inform your decisions. Strengthen your ability to organise a data infrastructure aligned with expected services.
- Duration
- 5 days 35 hours
- Code
- ASR007FR Code
- Certification
- Splunk® Enterprise Certified Admin Certification
Accredited training for the Splunk® Enterprise Certified Admin certification.
Presentation
In data-driven organisations, maintaining a healthy, high-performing analytics platform is a major operational priority. Daily management of Splunk Enterprise environment components requires specialist skills, from licence administration to search head configuration. This intermediate-level course is specifically designed to validate administrators' technical ability to take responsibility for overall infrastructure health.
This intensive 5-day programme provides comprehensive immersion in the data lifecycle, from ingestion through forwarders to optimised storage in indexers. You will explore advanced parsing techniques, data normalisation through the CIM model and multi-tier retention strategies. Critical security issues, including data encryption and integration with external directory services, are also covered.
By the end of the course, your new expertise will enable you to ensure a stable, secure Splunk environment while resolving performance bottlenecks. You will also be ready to take the exam for the Splunk Enterprise Certified Admin credential. This professional certification demonstrates your ability to administer enterprise-wide data pipelines effectively.
Objectives
By the end of this Enterprise Admin course, you will be able to:
- manage key Splunk Enterprise components daily, including licences, indexers and search heads;
- configure data input and ingestion through methods such as APIs, Syslog and forwarders;
- master data parsing and normalisation through advanced configuration files and the CIM model;
- administer indexing strategies and storage lifecycles (buckets);
- secure the environment through role management, encryption and LDAP/SAML integration;
- optimise performance and monitor system health through the monitoring console;
- maintain, back up and troubleshoot Splunk components;
- prepare for and pass the Splunk Certified Enterprise Admin certification exam.
Program
Module 1: mastering data flows and management
- Identifying the Data Administrator's role.
- Understanding the complete data flow: input, processing, storage and search.
- Identifying supported data types (logs, metrics, events).
Hands-on exercises
- Analyse data flows in a standard Splunk environment.
Module 2: configuring advanced collection and ingestion
- Ingestion through files, APIs, databases and syslog.
- Configuring Universal and Heavy Forwarders.
- Using connectors and add-ons.
Hands-on exercises
- Implement log collection through a manually configured forwarder.
Module 3: managing parsing and CIM normalisation
- Managing configuration files (inputs.conf, props.conf, transforms.conf).
- Advanced parsing techniques using regular expressions.
- Data normalisation through the Common Information Model (CIM).
Hands-on exercises
- Extract complex fields and normalise data for a CIM application.
Module 4: administering indexing and buckets
- Creating and managing indexes.
- The storage lifecycle: hot, warm, cold and frozen buckets.
- Optimising storage and compression rates.
Hands-on exercises
- Define a retention policy and configure automatic archiving.
Module 5: securing access and infrastructure
- Managing roles, permissions and data anonymisation.
- Integrating LDAP, Active Directory and SAML.
- Data encryption (SSL/TLS) and activity auditing.
Hands-on exercises
- Configure external authentication and mask sensitive data.
Module 6: optimising performance and monitoring health
- Configuring resources (CPU, memory, cache).
- Distributed deployment (Indexer and Search Head Clustering).
- Overall monitoring through the Splunk Monitoring Console.
Hands-on exercises
- Diagnose a performance bottleneck through the monitoring console.
Module 7: maintaining and troubleshooting the environment
- Backup and restore procedures.
- Troubleshooting data pipelines and ingestion errors.
- Recommendations for ensuring a stable environment.
Audience
This course is designed for professionals responsible for the daily administration and reliability of Splunk data platforms, including:
- Splunk administrators seeking formal validation of their technical expertise in managing key components such as licences, indexers and search heads;
- systems engineers responsible for configuring large-scale data ingestion, managing forwarder deployments and monitoring overall collection pipeline health;
- data architects and managers who need to master advanced parsing, CIM normalisation and bucket-based storage strategy optimisation;
- cybersecurity specialists seeking to implement rigorous access controls, configure LDAP/SAML authentication and encrypt sensitive data.
Prerequisites
The following prerequisites apply:
- Professional experience: practical proficiency at Splunk Core User level or equivalent log analysis experience is essential for this intermediate-level course.
- Technical skills: sound regular expression (Regex) knowledge, essential for advanced parsing, and basic system administration skills (Linux/Windows) are required.
- Language skills: good English reading comprehension is required, as the official certification exam is conducted exclusively in English.
- Certification: Splunk Core Certified Power User certification is mandatory to officially earn the Splunk Enterprise Certified Admin credential, but is not required to attend this course.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Recognised certification: acquire the skills needed to earn the official Splunk Certified Admin credential, demonstrating your expertise in the market.
- Ingestion expertise: configure complex data pipelines and optimise parsing through advanced configuration files.
- Enhanced security: learn to protect data through encryption, anonymisation and advanced directory service integration.
- Performance optimisation: master the monitoring console to manage cluster health and resolve infrastructure issues.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Splunk is a registered trademark of Cisco Systems, Inc. or its affiliates in the United States and other countries.
Mention for educational purposes does not constitute an endorsement or partnership.
fr
en