Splunk Education Student Handbook
Splunk Education Student Handbook
©Splunk Inc.
270 Brannan St.
San Francisco, CA
U.S.A.
SPLUNK EDUCATION
Student Handbook
Table of Contents
Program Introduction……………………………………………………………..……. 3
Delivery Methods………………….……………………………….............................. 4
Learning Paths……………………….……………………………………….………… 5
Certification……………………………………………………………………………… 21
Training Credits…………..………….…………………………………………………. 23
Course Registration………………………….………………………………………… 25
Candidate Support/FAQ……………………………………………………….………. 28
Splunk Policies…………………………………………………………………….……. 30
Welcome to the world of Splunk Education! From free courses to paid subscriptions, from a few
minutes to a few days, from your first day to your first deployment, we are here to help you get
the most out of Splunk—the Data to Everything platform.
Where do I start?
Great question! Here at Splunk, our Data-to-Everything Platform includes everything you need
to ensure your digital initiatives succeed… but how? Leverage our Splunk Education offerings to
empower your people to predict, identify, and solve problems in real time. We can teach you to
answer your own questions across business, IT, DevOps and security functions with world-class
investigative capabilities, intuitive visualizations, and seamless collaboration.
Splunk Education offers focused training programs that enable you to get started quickly and
stay relevant. We greatly enhance the value that Splunk can bring to you and your company.
Experience has shown that attending Splunk education can have an immediate and profound
impact on your staff and your organization. Our goal is to deliver the maximum amount of
practical information in the shortest amount of time to keep your downtime or
out-of-office time to a minimum. We focus on the tasks required to implement, manage,
develop and use Splunk, with the goal of helping you become self-sufficient and productive as
quickly as possible.
With such an extensive list of courses available, some students don’t know where to start (or
stop!). This is why we’ve put together Learning Paths designed to give students everything
they need to become true subject matter experts in their desired field.
All course prices shown are in US dollars.
The Search Expert learning path offers courses to teach you to write efficient searches, perform
correlations, create visualizations, and leverage subsearches and lookups.
COURSES PRICE
The Knowledge Manager learning path courses teach you to create knowledge objects including
lookups, data models, and different types of fields. In addition, you learn to build dashboards
and add inputs for filtering.
COURSE PRICE
The Data Science Analyst learning path courses teach you to write efficient and optimized
searches to extract analytics from your data. It covers machine learning, transaction analysis
COURSE PRICE
AND
COURSE PRICE
The Splunk Cloud Administrator learning path offers courses for admins to manage data inputs
and configurations in Splunk Cloud.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above and hold the Splunk Core Certified
Power User certification are eligible for the Splunk Cloud Certified Admin certification exams.
The Splunk Enterprise Administrator learning path teaches you the concepts, tasks, and best
practices to install, configure, and manage your deployment, and learn to onboard varying data.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above and hold the Splunk Core Certified
Power User certification are eligible for the Splunk Enterprise Certified Admin certification exam.
COURSE PRICE
The Splunk Enterprise Architect learning path teaches you concepts and best practices for
sizing, scaling, and deploying Splunk across your organization.
COURSE PRICE
AND
COURSE PRICE
The Splunk Enterprise Developer learning path teaches you how to harness the power of
Splunk's Web Framework, create rich, interactive dashboards and forms, and package Splunk
knowledge objects for distribution across your organization.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above and hold either the Splunk
Enterprise Certified Admin certification or the Splunk Cloud Certified Admin certification are
eligible for the Splunk Certified Developer certification exam.
The SOC Analyst learning path prepares security analysts to use Splunk Enterprise Security
(ES) and Mission Control. Students will use ES to identify and track security incidents, analyze
security risks, use predictive analytics, and threat discovery.
COURSE PRICE
AND
COURSE PRICE
The SOC Administrator learning path courses teach security admins to install, configure, and
manage Enterprise Security on Splunk Enterprise.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Enterprise
Security Certified Admin certification exam.
The SOC Administrator learning path courses teach security admins to configure and manage
Enterprise Security on Splunk Cloud.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above are eligible for the Splunk Enterprise
Security Certified Admin certification exam.
SOAR ANALYST
The SOAR Analyst learning path prepares security practitioners to use SOAR to respond to
security incidents, investigate vulnerabilities, and take action to mitigate and prevent security
problems.
COURSE PRICE
SOAR ADMINISTRATOR
The SOAR Administrator learning path teaches you how to install and configure SOAR, and
achieve orchestration and automation tasks through SOAR playbook development.
COURSE PRICE
Pro tip: Candidates who complete the learning path above are eligible for the Splunk SOAR
Certified Automation Developer certification exam.
The IT Analyst learning path teaches analysts to use Splunk IT Service Intelligence features,
such as Service Analyzer, Notable Events Review, Glass Tables, Deep Dives, KPI Alerts and
more.
COURSE PRICE
AND
COURSE PRICE
The IT Administrator learning path teaches admins to install, configure, and manage Splunk for
IT Service Intelligence (ITSI) on Splunk Enterprise.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above are eligible for the Splunk IT Service
Intelligence Certified Admin certification exam.
The IT Administrator learning path teaches admins to configure and manage Splunk for IT
Service Intelligence (ITSI) on Splunk Cloud.
COURSE PRICE
AND
COURSE PRICE
Pro tip: Candidates who complete the learning path above are eligible for the Splunk IT Service
Intelligence Certified Admin certification exam.
SPLUNK OBSERVABILITY
The Observability learning path for Site Reliability Engineer (SRE), DevOps and Developer
includes individual courses that teach the core skills on Infrastructure Monitoring, Application
Performance Management, Log Observer, Synthetics, Real User Monitoring and On-Call.
Learners may also wish to pursue Splunk Certifications on their journey to Splunk mastery.
Certifications offer substantial benefits to the individual, including earnings of an average of
16% more than their industry peers. Organizations that invest in Certification earn faster time
to value and are more likely to renew and expand their license.
How do certifications differ from learning paths? In simplest terms, certifications are
credentials which verify a candidate’s Splunk skills at a specific level. Learning paths are a
series of recommended courses designed to educate learners on a set of skills. Many
certification candidates choose to complete learning paths on their journey to become Splunk
Certified, but—in most cases— these courses are not required to qualify for the certification
exam (Splunk Enterprise Certified Architect and Splunk Certified Consultant are exceptions to
this rule and do require course completion. See certification tracks for more details.)
Our program offerings are outlined in the following table. Exam registration costs $130 USD for
a single exam or $500 USD for a discounted bundle of five registrations. Organizations can
convert EDU credits (not including those included with Success Plans) to certification vouchers
by emailing [email protected]. For more details, including program policies,
requirements, registration, and fees, check out the Splunk Certification Candidate Handbook.
Splunk Core Certified User Performs basic searches, uses fields, Splunk Enterprise
creates alerts, uses look-ups, and Splunk Cloud
creates basic statistical reports and
dashboards.
Splunk Core Certified Power User Understands SPL searching and Splunk Enterprise
reporting commands and creates Splunk Cloud
knowledge objects, uses field aliases
and calculated fields, creates tags and
event types, uses macros, creates
workflow actions and data models, and
normalizes data with the Common
Information Model.
Splunk Core Certified Advanced Power User Authors complex searches and Splunk Enterprise
reporting commands, implements Splunk Cloud
advanced use cases of knowledge
objects, and understands best
practices for building dashboards and
forms.
Splunk Certified Developer Builds apps using the Splunk Web Splunk Enterprise
Framework.
Splunk Enterprise Security Certified Admin Manages a Splunk Enterprise Security Splunk ES
environment, including ES event
processing and normalization,
deployment requirements, technology
add-ons, settings, risk analysis
settings, threat intelligence and
protocol intelligence configuration, and
customizations.
Splunk IT Service Intelligence Installs and configures Splunk's app Splunk ITSI
for IT Service Intelligence (ITSI),
including ITSI architecture, deployment
planning, service design and
implementation, notable events, and
developing glass tables and deep
dives.
Splunk SOAR Certified Automation Developer* Installs, configures, and uses SOAR Splunk SOAR
servers and plans, designs, creates,
and debugs basic playbooks for
Splunk SOAR. Understands complex
SOAR solution development, and can
integrate SOAR with Splunk as well as
develop playbooks requiring custom
coding and REST API usage.
*Formerly referred to as Splunk Phantom Certified Admin
TRAINING CREDITS
Each training credit is valued at $10 USD. The number of training credits required for each
course and delivery method can be found in the pricing list and the volume discounts are
outlined below.
*Please note, fifty (50) training credits can be converted to purchase a five-pack of certification
exam vouchers. Please send a request to [email protected] for assistance.
Splunk Education Basic eLearning subscription allows everyone in your organization to fully
utilize Splunk. For one year, anyone within a designated @company.com domain(s) can be
successful by completing the self-paced eLearning courses included in the subscription. Please
view additional information here Splunk Education Basic Subscription Datasheet.
The learner has the option to complete one or two learning paths or they can register and
complete the courses of their choice.
● What is Splunk?
● Intro to Splunk
● Using Fields
● Search Optimization
To register for a Splunk Education course, all students must first create a Splunk.com account.
Any issues encountered in creating an account or logging into an account should be directed to
Splunk Support (we recommend calling your regional helpline for the quickest assistance).
There are several ways to pay/register for a course (instructions can also be found here):
Once you’ve registered for a course, you will receive a confirmation email at the email address
you used to create your Splunk Education account with specific instructions. Please carefully
review these instructions, as they may include a system compatibility check which should be
completed prior to the start date of the course. This is especially true for instructor-led
courses.
When you’re ready to access your course, visit your training profile. Courses you have
registered for will be displayed at the bottom of the page. If you are having problems finding
your courses, click the My Learning tab, and use the Filter Results drop-down to filter courses
by status. Once you have found the course, click the View Details button for additional
instructions.
Similarly, access eLearning courses as described above or directly from the confirmation
email you received. If accessing from your training profile, click the Resume
Course/Pathway button to launch it.
Before launching a course, we suggest you use the test link at https://splk.it/2TKvg6K to verify
that it will work with your system or network.
Below are some of the most frequently-asked questions fielded by our Education Ops
Team. Please also refer to our Program Guide and Splunk Education FAQ for the most
up-to-date FAQ and information. Any questions not answered here can be directed to
[email protected] (regardless of region, this is our primary mailbox for
assistance).
Q: I completed an eLearning and want to practice the labs again. Can I regain access?
A: Each eLearning with Labs registration comes with access to labs up to three times. Each lab
access lasts up to four hours. You can access the labs by launching the course from your
profile. Additional lab time cannot be granted. Please note, to receive a certificate of completion
for the eLearning course, you need to complete the course and all labs within one of the four
hour lab sessions.
Q: I want to use my course materials to study for a certification exam, but no longer have
them. Where can I download them?
A: Please send a request to [email protected] for assistance.
Q: I have existing EDU credits. Can I use them for certification exam registration?
A: Yes! Fifty (50) training credits can be converted to purchase a five-pack of certification exam
vouchers. Please send a request to [email protected] for assistance. Partner credits
which were purchased at a discounted price of $5 USD per credit can be used, as well, with
(100) EDU credits equalling a five-pack of certification exam vouchers.
The above policies are not included in full in the Education Handbook as they are subject
to change and are best referenced via our website to ensure the most current, accurate
information is available.
Here is a complete list of our current paid course offerings, in alphabetical order. Please
see here for a list of free training resources.
Each of the below courses may include prerequisite courses. These courses include modules
and hands-on labs. Please visit the course pages for more information including course
descriptions, public class schedules and registration information.
Unsure of which courses you need? Please review the Learning Paths here. Looking for
continuing education courses to recertify with Splunk Certification? Please see our
Recertification Policy for which courses qualify for each specific certification track.
Automation Using the REST and SignalFlow API 9 $1,000 or 100 credits
Splunk for Analytics and Data Science 13.5 $1,500 or 150 credits