757-216-3656 | Monday–Friday 8:30 AM – 4:30 PM | info@itdojo.com

Course Duration

2 Days

Audience

Employees of federal, state and local governments; and businesses working with the government.

Prerequisites

Completion of Splunk Enterprise Data Administration (SP-SEDA) or equivalent. Solid understanding of Splunk distributed deployment, indexes, and forwarder configuration.

Course Description

This 2-day course provides the knowledge to deploy and manage Splunk Enterprise in a clustered environment for high availability and scalability. Students learn how indexer clustering and search head clustering work, how to configure and manage cluster masters and peers, and how to maintain a healthy clustered Splunk deployment at scale.

Learning Objectives

  • Describe factors that affect large-scale Splunk deployment design
  • Configure and manage an indexer cluster with a cluster master
  • Manage index replication and bucket fixup in an indexer cluster
  • Configure and administer a Splunk search head cluster
  • Use the deployer to push configurations to search head cluster members
  • Monitor cluster health and troubleshoot common cluster issues
  • Perform rolling upgrades on indexer and search head clusters

Course Outline

Large-scale Deployment Overview
  • Factors affecting large-scale design
  • Scaling Splunk Enterprise
  • License management at scale
Indexer Clustering
  • Indexer cluster architecture
  • Configuring the cluster master
  • Configuring cluster peers
  • Managing replication and search factor
  • Bucket fixup and cluster maintenance
Search Head Clustering
  • Search head cluster architecture
  • Configuring the deployer
  • Adding and removing cluster members
  • Troubleshooting search head clusters
Cluster Maintenance
  • Monitoring cluster health
  • Rolling upgrades
  • Common cluster troubleshooting scenarios

Frequently Asked Questions

What does Splunk Enterprise Cluster Administration cover?

This 2-day course covers indexer clustering and search head clustering -- the advanced administration topics needed to manage large-scale, highly available Splunk deployments.

What are the prerequisites?

Completion of SP-SEDA (Splunk Enterprise Data Administration) or equivalent. You should be comfortable with Splunk distributed search, indexes, and forwarder configuration before attending.

Is this course part of the Splunk Enterprise Certified Admin path?

Yes. Cluster administration is included in the Splunk Enterprise Certified Admin certification exam content.

Is this course available as live remote online training?

Yes. IT Dojo offers this course as live remote online instruction. On-site delivery is also available.

How do I register?

IT Dojo training is employer sponsored. Contact IT Dojo via the Request Training form or call 757-216-3656.

Get More Information

We work with Government Agencies, Military, government contractors, and corporate clients. As much as we would love to, our business model does not include working with the general public.