Splunk Education Student Handbook
Splunk Education Student Handbook
2021
©Splunk Inc.
270 Brannan St.
San Francisco, CA
U.S.A.
SPLUNK EDUCATION
Student Handbook
Table of Contents
Program Introduction……………………………………………………………..……. 3
Learning Paths……………………….………………………………………….………. 6
Training Credits…………..………….…………………………………………………. 17
Candidate Support/FAQ………………………………………………………….……… 19
Welcome to the world of Splunk Education! From free courses to paid subscriptions, from a few
minutes to a few days, from your first day to your first deployment we are here to help you get the
most out of Splunk—the Data to Everything platform.
Where do I start?
Great question! Here at Splunk, our Data-to-Everything Platform includes everything you need to
ensure your digital initiatives succeed… but how? Leverage our Splunk Education offerings to
empower your people to predict, identify, and solve problems in real time. We can teach you to
answer your own questions across business, IT, DevOps and security functions with world-class
investigative capabilities, intuitive visualizations, and seamless collaboration.
Splunk Education offers focused training programs that enable you to get started quickly and stay
relevant. We greatly enhance the value that Splunk can bring to you and your company. Experience
has shown that attending Splunk education can have an immediate and profound impact on your
staff and your organization. Our goal is to deliver the maximum amount of practical
information in the shortest amount of time to keep your downtime or out-of-office time to a
minimum. We focus on the tasks required to implement, manage, develop and use Splunk, with the
goal of helping you become self-sufficient and productive as quickly as possible.
● Self-paced eLearning
These courses give students a 30-day window (beginning on the date of registration) to
complete the course at their convenience.
Want more free content? Of course you do! Please see here for additional resources including
micro-training, use-case videos, platform walk-throughs, and more!
With such an extensive list of courses available, some students don’t know where to start (or stop!).
This is why we’ve put together Learning Paths designed to give students everything they need to
become true subject matter experts in their desired field.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Splunk for Analytics and Data Science
● Splunk Infrastructure Overview
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Core
Certified User, Splunk Core Certified Power User, and Splunk Core Certified Advanced Power
User certification exams (in that order).
● Fundamentals 1
● Fundamentals 2
● Splunk Enterprise System Administration
● Splunk Enterprise Data Administration
● Troubleshooting Splunk Enterprise
● Splunk Enterprise Cluster Administration
● Implementing Splunk SmartStore
● Splunk Workload Management
● Working with Metrics in Splunk
● Implementing Splunk Data Stream Processor
Pro tip: Candidates who complete the learning path above and hold the Splunk Core Certified
Power User certification are eligible for the Splunk Enterprise Certified Admin certification exam.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Splunk for Analytics and Data Science
● Splunk Cloud Administration
● Transitioning to Splunk Cloud
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Core
Certified User, Splunk Core Certified Power User, and Splunk Core Certified Advanced Power
User or the Splunk Cloud Certified Admin certification certification exams (in that order). Please
see the certification tracks for more information.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Splunk Enterprise System Administration
● Splunk Enterprise Data Administration
● Troubleshooting Splunk Enterprise
● Splunk Enterprise Cluster Administration
● Architecting Splunk Enterprise Deployments
Pro tip: Candidates who complete the learning path above, the Splunk Enterprise Practical Lab,
and hold the Splunk Enterprise Certified Admin certification are eligible for the Splunk Enterprise
Certified Architect certification exam.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Advanced Dashboards & Visualizations
● Building Splunk Apps
● Developing with Splunk's REST API
Pro tip: Candidates who complete the learning path above and hold either the Splunk Enterprise
Certified Admin certification or the Splunk Cloud Certified Admin certification are eligible for the
Splunk Certified Developer certification exam.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Splunk Enterprise System Administration
● Splunk Enterprise Data Administration
● Architecting Splunk Enterprise Deployments
● Administering Splunk Enterprise Security
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Enterprise
Security Certified Admin certification exam.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Using Splunk Enterprise Security
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Splunk Enterprise System Administration
● Splunk Enterprise Data Administration
● Implementing Splunk IT Service Intelligence
Pro tip: Candidates who complete the learning path above are eligible for the Splunk IT Service
Intelligence Certified Admin certification exam.
● Fundamentals 1
● Fundamentals 2
● Fundamentals 3
● Creating Dashboards with Splunk
● Advanced Searching & Reporting
● Using Splunk IT Service Intelligence
Splunk Education's learning path for Phantom customers teaches you how to install and configure
Phantom, and achieve orchestration and automation tasks through Phantom playbook development.
● Administering Phantom
● Developing Phantom Playbooks
● Advanced Phantom Implementation
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Phantom
Certified Admin certification exam.
To register for a Splunk Education course, all students must first create a Splunk.com account. Any
issues encountered in creating an account or logging into an account should be directed to Splunk
Support (we recommend calling your regional help line for the quickest assistance).
There are several ways to pay/register for a course (instructions can also be found here):
Once you’ve registered for a course, you will receive a confirmation email at the email address you
used to create your Splunk Education account with specific instructions. Please carefully review
these instructions, as they may include a system compatibility check which should be completed
prior to the start date of the course. This is especially true for instructor-led courses.
When you’re ready to access your course, visit your training profile. Courses you have registered
for will be displayed at the bottom of the page. If you are having problems finding your courses,
click the My Learning tab, and use the Filter Results drop-down to filter courses by status. Once
you have found the course, click the View Details button for additional instructions.
Similarly, access eLearning/IOD courses as described above or directly from the confirmation
email you received. If accessing from your training profile, click the Resume Course/Pathway
button to launch it. Remember: eLearning/IOD classes have a 30-day time limit. This clock
starts as soon as you start the course.
Before launching a course, we suggest you use the test link at https://splk.it/2TKvg6K to verify
that it will work with your system or network.
Splunk Education offers training credits to provide flexibility and volume discounts. Training credits
can be used for all education offerings, delivery methods and certification exams*. Training credits
can also be used by anyone within your organization to provide the right training, at the right time,
throughout the 12-month term.
Each training credit is valued at $500/credit. The number of training credits required for each class
and delivery method can be found here https://education.splunk.com/pricing and the volume
discounts are outlined below.
50 $25,000 2% $24,500
*Please note, Splunk Education uses the passkey or SO to pay for the course. Splunk Certification exams
require voucher codes for use on the Pearson VUE platform. To request an exam registration voucher,
please contact [email protected] (and include your SO in the request).
Splunk Education Instructor On-Demand (IOD) subscriptions allow everyone in your organization
to fully utilize Splunk. For one year, anyone within a single @company.com domain can be successful
by completing the self-paced IOD courses included in each subscription.
Please view additional information here Splunk Education Instructor On-Demand (IOD)
Subscriptions. Please contact [email protected] for pricing.
Below are some of the most frequently-asked questions fielded by our Education Ops Team.
Please also refer to our Program Guide and Splunk Education FAQ for the most up-to-date FAQ
and information. Any questions not answered here can be directed to
[email protected] (regardless of region, this is our primary mailbox for assistance).
Q: I was unable to complete my eLearning/IOD course within the 30 days. Can I request an extension?
A: Please send a request to [email protected] to see if you are eligible for an
extension. Note that an administrative fee may be due.
Q: I completed an eLearning/IOD course and want to practice the labs again. Can I regain access?
A: No. Once a course has been completed and expired, we cannot grant additional access.
Q: I want to use my course materials to study for a certification exam, but no longer have them. Where
can I download them?
A: Please send a request to [email protected] for assistance.
Q: I have existing EDU credits. Can I use them for certification exam registration?
A: Yes! One (1) EDU credit can be used to purchase a five-pack of exam registration vouchers. Please
send a request to [email protected] for assistance. Partner credits which were purchased
at a discounted price of $250/credit can be used, as well, with (2) EDU credits equalling a five-pack
of exam registration vouchers.
The above policies are not included in full in the Education Handbook as they are subject to
change and are best referenced via our website to ensure the most current, accurate
information is available.
Here is a complete list of our current paid course offerings, in alphabetical order.
Each of the below courses may include prerequisite coursework. These courses include modules, labs,
and may include quizzes or knowledge checks. Please visit the course pages linked in each header for
more information, as well as scheduling and registration information.
Unsure of which courses you need? Please review the Learning Paths here. Looking for continuing
education courses to recertify with Splunk Certification? Please see our Recertification Policy for
which courses qualify for each specific certification track.
ADMINISTERING PHANTOM
This 9-hour course prepares IT and security practitioners to install, configure and use a Phantom
server in their environment and will prepare developers to attend the playbook development
course. download pdf ($1,000/2 credits)
FUNDAMENTALS PART 1
This 9-hour course teaches you how to search and navigate in Splunk, use fields, get statistics from
your data, create reports, dashboards, lookups, and alerts. Scenario-based examples and hands-on
challenges will enable you to create robust searches, reports, and charts. It will also introduce you
to Splunk's datasets features and Pivot interface. download pdf ($1,000/2 credits)
FUNDAMENTALS PART 2
This 18-hour course focuses on searching and reporting commands as well as on the creation of
knowledge objects. Major topics include using transforming commands and visualizations, filtering
and formatting results, correlating events, creating knowledge objects, using field aliases and
calculated fields, creating tags and event types, using macros, creating workflow actions and data
models, and normalizing data with the Common Information Model (CIM). download pdf ($2,000/4
credits)
FUNDAMENTALS PART 3
This 18-hour course focuses on additional search commands as well as advanced use of knowledge
objects. Major topics include advanced statistics and eval commands, advanced lookup topics,
advanced alert actions, using regex and erex to extract fields, using spath to work with
self-referencing data, creating nested macros and macros with event types, and accelerating reports
and data models. download pdf ($2,000/4 credits)
Please note: Search head clustered deployment topics will NOT be covered in this class.
Please note: While Splunk Clusters are supported in Windows environments, the class lab
environment is running Linux instances only.
Please note: This course does not cover the issues surrounding Splunk Cloud, Splunk Clusters, or
Splunk premium apps.
The above policies are not included in full in the Education Handbook as they are subject to
change and are best referenced via our website to ensure the most current, accurate
information is available.