User Tools

Site Tools


Splunk Foundation and Data Analytics


This is an IN-PERSON track on the Collin College campus


Dive into fundamental concepts with expert instruction on Splunk, the leading platform that helps bring data to every question, decision and action across organizations.

This hands on track will immerse you in topics that can take any beginner from writing their first basic queries, to assembling dashboards and managing knowledge objects, to having greater command of the Splunk Search Processing Language (SPL), and more. By the end of the week, you will have investigated and analyzed different datasets, and be equipped with ample knowledge to take our Splunk Power User certification. This track also teaches the prerequisite skills to attend more advanced training that will help you bring Splunk to your classrooms.

Learn more about Splunk and this track by watching this 14-minute video.


What is Splunk? (eLearning) -
Intro to Splunk (eLearning) -
Visualizations (eLearning) -




Haya Husain is a Technical Instructor who teaches classes regarding the Splunk Observability Cloud and Splunk core products. Haya has a background as a Client Support Engineer and Lead Technical Instructor in the healthcare IT field. She is passionate about making technical education both effective and fun! She also enjoys learning about cybersecurity and completed her Masters degree in Identity Management and Security from UT Austin in 2020. In her free time, she enjoys playing ice hockey and baking.

Course Objectives

At the completion of this track, the participants will be able to…

  • Describe foundational, core Splunk concepts - enough to prepare for the Splunk Power User certification exam.
  • Understand the structure of using SPL, and practice commands that are key to investigating, analyzing and presenting data.
  • Create and manage knowledge objects that are critical in many organizations, including dashboards, reports and field extractions.
  • Pick up prerequisite knowledge and skills for our other advanced training including courses on data administration, security and data science.

Topics Agenda

Click here for the program schedule and times.

  • Working With Time
    • Searching with Time
    • Formatting Time
    • Comparing Index Time versus Search Time
    • Using Time Commands
    • Working with Time Zones
  • Result Modification
    • Manipulating Output
    • Modifying Result Sets
    • Managing Missing Data
    • Modifying Field Values
    • Normalizing with eval
  • Statistical Processing
    • What is a Data Series
    • Report Acceleration
    • Transforming Data
    • Manipulating Data with eval
    • Formatting Data
  • Comparing Values
    • Using eval to Compare
    • Filtering with where
  • Correlation Analysis
    • Calculate Co-Occurrence Between Fields
    • Analyze Multiple Datasets
  • Creating Field Extractions
    • Using the Field Extractor
    • Creating Regex Field Extractions
    • Creating Delimited Field Extractions
  • Creating Knowledge Objects
    • Knowledge Objects and Search-time Operations
    • Creating Event Types
    • Using Event Type Builder
    • Creating Workflow Actions
    • Creating Tags and Aliases
    • Creating Search Macros
  • Data Models
    • Introducing Data Model Datasets
    • Designing Data Models
    • Creating a Pivot
    • Accelerating Data Models
  • Using Fields
    • What are Fields?
    • What is Field Discovery?
    • Using Fields in Searches
    • Comparing Temporary versus Persistent Fields
    • Enriching Data
  • Leveraging Lookups & Subsearches
    • Using Lookup Commands
    • Adding a Subsearch
    • Using the return Command

Please note that content is subject to change or modification based on the unique needs of the track participants in attendance.

splunk.txt · Last modified: 2022/07/05 15:32 by admin