Splunk Advanced Power User Fast Start (APU-FT) - english virtual



Kursarrangør: Glasspaper AS
Sted: Nettkurs / Nettstudie
Hele landet
Type:Nettkurs og nettstudie
Studie / yrkesutdanning
Undervisningstid: kl 09:00 - 17:00
Varighet: 3 days
Pris: 34.500
Neste kurs: 17.08.2026 | Vis alle kursdatoer

We provide virtual course about Splunk Advanced Power User Fast Start (APU-FT) in english. For power users who want to become experts on searching and manipulating multivalue data.

Course description:
This Advanced Power User Fast Start is:
1) Topics will focus on using multivalue eval functions and multivalue commands to create, evaluate, and analyze multivalue data.

2) Designed for power users who want to learn how to use lookups and subsearches to enrich their results. Topics will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources.

3) For power users who want to improve search performance. Topics will cover how search modes affect performance, how to create an efficient basic search, how to accelerate reports and data models, and how to use the tstats command to quickly query data.

4) For knowledge managers who want to use lookups to enrich their search environment. Topics will introduce lookup types and cover how to upload and define lookups, create automatic lookups, and use advanced lookup options. Additionally, students will learn how to verify lookup contents in search and review lookup best practices.

5) Designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on dashboard creation, including prototyping, the dashboard definition, layouts types, adding visualizations, and dynamic coloring.

6) Designed for power users who want to learn best practices for building dashboards in the Dashboard Studio. It focuses on creating inputs, chain searches, event annotations, and improving dashboard performance.

Course objectives:
• Using Lookup Commands
• Adding a Subsearch
• Using the return Command
• What are Multivalue Fields
• Creating Multivalue Fields
• Evaluating Multivalue Fields
• Analyzing Multivalue Fields
• Optimizing Search
• Report Acceleration

• Data Model Acceleration
• Using the tstats Command
• What is a Lookup
• Creating Lookups
• Geospatial Lookups
• External Lookups
• KV Store Lookups
• Best Practices for Lookups
• Dashboard Framework

• Prototyping
• Visualization Types
• Modifying the Source Code
• Dynamic Coloring
• Data Source Types
• Mock Data
• Event Annotations
• Adding Inputs
• Chain Searches

Course outline:
Module 1 - Leveraging Lookups and Subsearches (SSC):
• Using Lookup Commands
• Adding a Subsearch
• Using the return Command

Module 2 - Multivalue Fields (SSC):
• What are Multivalue Fields
• Creating Multivalue Fields
• Evaluating Multivalue Fields

Module 3 - Search Optimization (SSC):
• Optimizing Search
• Report Acceleration
• Data Model Acceleration
• Using the tstats Command

Module 4 - Enriching Data With Lookups (SSC):
• What is a Lookup
• Creating Lookups
• Geospatial Lookups
• External Lookups
• KV Store Lookups
• Best Practices for Lookups

Module 5 - Intro To Dashboards (SSC):
• Dashboard Framework
• Create a Prototype
• Use Dynamic Coloring

Module 6 - Dynamic Dashboards (SSC):
• TSelecting a Data Source
• Adding Inputs
• Improving Performance
• Comparing Temporary versus Persistent Fields
• Enriching Data

Target audience:
Search Experts Knowledge Managers

Prerequisites:
To be successful, students should have a solid understanding of the following:
• How Splunk works
• Knowledge objects
• Lookups
• Creating Search queries
• Creating reports and data models
• Data structure requirements for visualizations
• The dashboard definition

Language:
• English course material and english speaking instructor

Course material:
The course fee includes digital course documentation and hands-on labs

Certification:
This course is part of the following certifications: Splunk Core Certified Advanced Power User