Transitioning to Splunk Cloud (SP-TSC)
Schedule
- T88256
- 2 days
- 04/30/2026 - 05/01/2026*
- 9:00 AM
- (GMT -04:00) Eastern Daylight Time
- Presented via WebEx
- VC
Virtual Classroom
Attend any of our instructor-led classes virtually regardless of your physical location.
- VC
- PC
Private Class
Privately train a group of your employees at your facility, virtually, or any of our locations.
- PC
- LCLive Classroom
Live Classroom
Learn and interact with your instructor and peers in-person in our classrooms. - VCVirtual Classroom
Virtual Classroom
Attend any of our instructor-led classes virtually regardless of your physical location. - PCPrivate Class
Private Class
Privately train a group of your employees at your facility, virtually, or any of our locations. - GTRGuaranteed to Run
Guaranteed to Run
GTR classes are guaranteed to run as promised and delivered.
*event may not be applicable to special offers or promotions.
Course Summary
Show All
Description
For Splunk Administrators who have undertaken the System and Data Administration learning pathways, this course highlights key differences between Splunk Enterprise deployed on-premises and Splunk Enterprise Cloud to allow them to ramp up their data and system management skills to transition to Splunk Cloud. The hands-on lab provides access to and experience of managing a Splunk Cloud instance.
Note: Splunk Cloud Administration and Transitioning to Splunk Cloud SHOULD NOT be taken together as both aredesigned to develop Splunk Cloud-specific skills and as such there is some overlap.
Prerequisites
To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:
○ Intro to Splunk
○ Using Fields
○ Introduction to Knowledge Objects
○ Creating Knowledge Objects
○ Creating Field Extractions
○ Splunk Enterprise System Administration
○ Splunk Enterprise Data Administration
Additional courses and/or knowledge in these areas are also highly recommended:
○ Enriching Data with Lookups
○ Data Models
Outline
Module 1 – Splunk Cloud Overview
- Describe Splunk and Splunk Cloud features and topology
- Identify Splunk Cloud administrator tasks
- Describe Splunk Cloud purchasing options and differences between Classic and Victoria experience
- Secure Splunk deployments best practices
- Explain Splunk Cloud data ingestion strategies
Module 2 – Splunk Cloud Migration
- Understand the Splunk Cloud migration journey
- Determine Splunk Cloud migration readiness
- Identify Splunk Cloud migration preparation tasks, strategies, and possible challenges
Module 3 – Managing Users
- Identify Splunk Cloud authentication options
- Add Splunk users using native authentication
- Integrate Splunk with LDAP, Active Directory or SAML
- Create a custom role
- Manage users in Splunk
- Use Workload Management to manage user resource usage
Module 4 – Managing Indexes
Understand cloud indexing strategy
Define and create indexes
Manage data retention and archiving
Delete and mask data from an index
Monitor indexing activities
Module 5 – Managing Apps
- Review the process for installing apps
- Define the purpose of private apps
- Upload private apps
- Describe how apps are managed
Module 6 – Configuring Forwarders
- List Splunk forwarder types
- Understand the role of forwarders
- Configure a forwarder to send data to Splunk Cloud
- Test the forwarder connection
- Describe optional forwarder settings
Module 7 – Common Inputs
- Describe forwarder inputs such as files and directories
- Create REST API inputs
- Create a basic scripted input
- Create Splunk HTTP Event Collector (HEC) agentless inputs
Module 8 – Additional Inputs
- Understand how inputs are managed using apps or add-ons
- Explore Cloud inputs using Splunk Connect for Syslog, Data Manager, Inputs Data Manager (IDM), Splunk Edge Processor, and Splunk Edge Hub
Module 9 – Using Ingest Actions
- Explore Splunk transformation methods
- Create and manage rulesets with Ingest Actions
- Mask, filter and route data with Ingest Action rules