{"product_id":"splunk-enterprise-data-administration-spseda","title":"Splunk Enterprise Data Administration (SPSEDA)","description":"\u003cdiv\u003e\u003cp\u003eThis course is designed for administrators who are responsible for getting data into Splunk Indexers. The course provides the fundamental knowledge of Splunk forwarders and methods to get remote data into Splunk indexers. It covers installation, configuration, management, monitoring, and troubleshooting of Splunk forwarders and Splunk Deployment Server components.\u003c\/p\u003e\u003c\/div\u003e\u003cdiv\u003e\n\u003ch3\u003eSplunk Enterprise Data Administration (SPSEDA) Benefits\u003c\/h3\u003e\n\u003cul\u003e\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eKey Features\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eThis course is a core component of the \u003ca href=\"https:\/\/www.flane.co.uk\/certification\/seca\" rel=\"nofollow noopener\" target=\"_blank\"\u003eSplunk Enterprise Certified Admin\u003c\/a\u003e certification.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eWhat You'll Learn\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIngest and manage diverse data sources within Splunk.\u003c\/li\u003e\n\u003cli\u003eDeploy and administer Splunk Forwarders.\u003c\/li\u003e\n\u003cli\u003eCustomize and optimize data processing pipelines.\u003c\/li\u003e\n\u003cli\u003eEffectively transform and route incoming data.\u003c\/li\u003e\n\u003cli\u003eImplement and maintain search-time knowledge objects.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003ePrerequisites\u003c\/strong\u003e For the best learning outcome, students should have completed the following Splunk Education courses or possess equivalent working knowledge:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIntro to Splunk\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.flane.co.uk\/course\/splunk-suf\" rel=\"nofollow noopener\" target=\"_blank\"\u003eUsing Fields (SUF)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003eIntro to Knowledge Objects\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.flane.co.uk\/course\/splunk-cko\" rel=\"nofollow noopener\" target=\"_blank\"\u003eCreating Knowledge Objects (CKO)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.flane.co.uk\/course\/splunk-cfe\" rel=\"nofollow noopener\" target=\"_blank\"\u003eCreating Field Extractions (CFE)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.flane.co.uk\/course\/splunk-edl\" rel=\"nofollow noopener\" target=\"_blank\"\u003eEnriching Data with Lookups (EDL)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.flane.co.uk\/course\/splunk-sdm\" rel=\"nofollow noopener\" target=\"_blank\"\u003eData Models (SDM)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003eSplunk Enterprise System Administration (SP-SESA)\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eWho Should Attend\u003c\/strong\u003e This course is designed for Splunk Administrators.\u003c\/p\u003e\n\u003c\/li\u003e\u003c\/ul\u003e\n\u003c\/div\u003e\u003cdiv\u003e\u003ch3\u003eSplunk Data Admin Course Outline\u003c\/h3\u003e\u003c\/div\u003e\u003cdiv\u003e\n\u003ch4\u003eLearning Objectives\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eModule 1 – Get Data Into Splunk\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eProvide an overview of Splunk\u003c\/li\u003e\n\u003cli\u003eDescribe the Splunk distributed model\u003c\/li\u003e\n\u003cli\u003eDescribe data input types and metadata settings\u003c\/li\u003e\n\u003cli\u003eConfigure initial input testing with Splunk Web\u003c\/li\u003e\n\u003cli\u003eTest Indexes with input staging\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 2 – Configuration Files and Apps\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eIdentify Splunk configuration files and directories\u003c\/li\u003e\n\u003cli\u003eDescribe index-time and search-time precedence\u003c\/li\u003e\n\u003cli\u003eValidate and update configuration files\u003c\/li\u003e\n\u003cli\u003eExplore Splunk apps and apps installation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 3 – Configure Forwarders\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eConfigure Universal Forwarders\u003c\/li\u003e\n\u003cli\u003eConfigure Heavy Forwarders\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 4 – Customize Forwarder\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eConfigure intermediate forwarders\u003c\/li\u003e\n\u003cli\u003eIdentify additional forwarder options\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 5 - Manage Forwarders\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eDescribe the Splunk deployment server\u003c\/li\u003e\n\u003cli\u003eManage forwarders using deployment apps\u003c\/li\u003e\n\u003cli\u003eConfigure deployment clients and client groups\u003c\/li\u003e\n\u003cli\u003eMonitor forwarder management activities\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 6 – Monitor Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eCreate file and directory monitor inputs\u003c\/li\u003e\n\u003cli\u003eUse optional settings for monitor inputs\u003c\/li\u003e\n\u003cli\u003eDeploy a remote monitor input\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 7 – Network Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eCreate network (TCP and UDP) inputs\u003c\/li\u003e\n\u003cli\u003eDescribe optional settings for network inputs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 8 – Scripted Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eCreate a basic scripted input\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 9 – Agentless Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eConfigure Splunk HTTP Event Collector (HEC) agentless input\u003c\/li\u003e\n\u003cli\u003eDescribe Splunk App for Stream\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 10 – Operating System Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eIdentify Linux-specific inputs\u003c\/li\u003e\n\u003cli\u003eIdentify Windows-specific inputs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 11 – Fine-tuning Inputs\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eUnderstand the default processing that occurs during input phase\u003c\/li\u003e\n\u003cli\u003eConfigure input phase options\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 12 – Parsing Phase and Data Preview\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eUnderstand the default processing during parsing phase\u003c\/li\u003e\n\u003cli\u003eOptimize and configure event line breaking\u003c\/li\u003e\n\u003cli\u003eExplain how timestamps and time zones are used\u003c\/li\u003e\n\u003cli\u003eUse Data Preview to validate event create during parsing phase\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 13 – Manipulating Input Data\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eExplore Splunk transformation methods\u003c\/li\u003e\n\u003cli\u003eCreate rulesets with Ingest Actions\u003c\/li\u003e\n\u003cli\u003eMask data with Ingest Actions rules\u003c\/li\u003e\n\u003cli\u003eMask data with SEDCMD and TRANSFORMS\u003c\/li\u003e\n\u003cli\u003eOverride sourcetype or host base upon event values\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 14 - Routing Input Data\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eFilter data with Ingest Action rules\u003c\/li\u003e\n\u003cli\u003eRoute data with Ingest Action rules\u003c\/li\u003e\n\u003cli\u003eRoute data with Transforms\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cb\u003eModule 15 – Supporting Knowledge Objects\u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eDefine default and custom search time field extractions\u003c\/li\u003e\n\u003cli\u003eIdentify the pros and cons of indexed time field extractions\u003c\/li\u003e\n\u003cli\u003eConfigure indexed field extractions\u003c\/li\u003e\n\u003cli\u003eDescribe default search-time extractions\u003c\/li\u003e\n\u003cli\u003eManage orphaned knowledge objects\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e","brand":"Fast Lane","offers":[{"title":"269C39EN \/ 2026-09-16T08:00:00 \/ Online","offer_id":53278477943150,"sku":"US-2717-IL","price":0.0,"currency_code":"USD","in_stock":true},{"title":"26CB37EN \/ 2026-12-16T08:00:00 \/ Online","offer_id":53278477975918,"sku":"US-2717-IL","price":0.0,"currency_code":"USD","in_stock":true}],"url":"https:\/\/learningtreeinternationalsita.myshopify.com\/products\/splunk-enterprise-data-administration-spseda","provider":"SITA Training","version":"1.0","type":"link"}