Splunk core and Power User Certification

所在平台: Udemy

课程主页: https://www.udemy.com/course/splunk-core-and-power-user-certification/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** Splunk 核心与高级用户认证 **课程概述:** 本课程旨在帮助学员为 Splunk 核心高级用户认证考试做准备。学员将深入学习 Splunk 搜索处理语言 (SPL) 的强大功能,掌握搜索、报告、创建知识对象(如字段别名、计算字段、标签、事件类型、宏、工作流操作和数据模型)以及使用通用信息模型 (CIM) 在 Splunk Enterprise 和 Splunk Cloud 平台中规范化数据。成功完成课程并获得认证,将证明学员具备 Splunk 核心软件的基础能力。 **课程目标:** 本课程涵盖了 Splunk 核心功能的关键方面,具体学习内容包括: * **模块 1:引言** * Buttercup Games Inc. 公司概览 * 实验室环境介绍 * **模块 2:搜索基础进阶** * 回顾搜索基础知识 * 区分大小写 * 使用作业检查器分析搜索性能 * **模块 3:使用转换命令进行可视化** * 探索数据结构要求 * 了解可视化类型 * 创建和格式化图表及时间序列图 * **模块 4:使用映射和单值命令** * `iplocation` 命令 * `geostats` 命令 * `geom` 命令 * `addtotals` 命令 * **模块 5:过滤和格式化结果** * `eval` 命令 * 使用 `search` 和 `where` 命令过滤结果 * `filnull` 命令 * **模块 6:关联事件** * 识别事务 * 使用字段对事件进行分组 * 使用字段和时间对事件进行分组 * 使用事务进行搜索 * 报告事务 * 确定何时使用事务与统计命令 * **模块 7:知识对象入门** * 命名约定 * 权限管理 * 管理知识对象 * **模块 8:创建和管理字段** * 使用字段提取器 (FX) 执行正则表达式字段提取 * 使用 FX 执行分隔符字段提取 * **模块 9:创建字段别名和计算字段** * 描述、创建和使用字段别名 * 描述、创建和使用计算字段 * **模块 10:创建标签和事件类型** * 创建和使用标签 * 描述事件类型及其用途 * 创建事件类型 * **模块 11:创建和使用宏** * 描述宏 * 创建和使用基本宏 * 定义宏的参数和变量 * 添加和使用参数 * **模块 12:创建和使用工作流操作** * 描述 GET、POST 和搜索工作流操作的功能 * 创建 GET 工作流操作 * 创建 POST 工作流操作 * 创建搜索工作流操作 * **模块 13:创建数据模型** * 描述数据模型与 Pivot 之间的关系 * 识别数据模型属性 * 创建数据模型 * 在 Pivot 中使用数据模型 * **模块 14:使用通用信息模型 (CIM) 插件** * 描述 Splunk CIM * 列出 Splunk CIM 插件中的知识对象 * 使用 CIM 插件规范化数据

课程评论(0条)

课程详情

Splunk Core Certified Power User Exam Test questionsA Splunk Core Certified Power User has a basic understanding of SPL searching, reporting commands can create knowledge objects, use field aliases and calculated fields, create tags and event types, use macros, create workflow actions and data models, and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms. This certification demonstrates an individual's foundational competence of Splunk's core software.Course ObjectivesModule 1 - IntroductionOverview of Buttercup Games Inc.Lab environmentModule 2 - Beyond Search FundamentalsSearch fundamentals reviewCase sensitivityUsing the job inspector to view search performanceModule 3 - Using Transforming Commands for VisualizationsExplore data structure requirementsExplore visualization typesCreate and format charts and timechartsModule 4 - Using Mapping and Single Value CommandsThe iplocation commandThe geostats commandThe geom commandThe addtotals commandModule 5 - Filtering and Formatting ResultsThe eval commandUsing the search and where commands to filter resultsThe filnull commandModule 6 - Correlating EventsIdentify transactionsGroup events using fieldsGroup events using fields and timeSearch with transactionsReport on transactionsDetermine when to use transactions vs. statsModule 7 - Introduction to Knowledge ObjectsIdentify naming conventionsReview permissionsManage knowledge objectsModule 8 - Creating and Managing FieldsPerform regex field extractions using the Field Extractor(FX)Perform delimiter field extractions using the FXModule 9 - Creating Field Aliases and Calculated FieldsDescribe, create, and use field aliasesDescribe, create and use calculated fieldsModule 10 - Creating Tags and Event TypesCreate and use tagsDescribe event types and their usesCreate an event typeModule 11 - Creating and Using MacrosDescribe macrosCreate and use a basic macroDefine arguments and variables for a macroAdd and use arguments with a macroModule 12 - Creating and Using Workflow ActionsDescribe the function of GET, POST, and Search workflowactionsCreate a GET workflow actionCreate a POST workflow actionCreate a Search workflow actionModule 13 - Creating Data ModelsDescribe the relationship between data models and pivotIdentify data model attributesCreate a data modelUse a data model in pivotModule 14 - Using the Common Information Model (CIM) Add-OnDescribe the Splunk CIMList the knowledge objects included with the Splunk CIMAdd-OnUse the CIM Add-On to normalize data

课程标签

0人关注该课程

主题相关的课程