Splunk: data, searching and alerts for security monitoring
How data reaches Splunk (forwarders, indexers, search heads, indexes and default fields), how to write efficient SPL searches for investigations (filter early, stats, timechart, top, sort, dedup, where, rex, NOT versus !=, time modifiers) and how to build alerts that don't flood the team (scheduled versus real-time, schedule and time range, delay, throttling), with knowledge objects and role-based access.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Splunk
Skills you'll practise
- Describe what the universal forwarder, indexer and search head each do
- Use host, source, sourcetype, index and _time to narrow a search before processing it
- Write a search pipeline that filters, aggregates and sorts results with stats, top, timechart and sort
- Explain the difference between NOT field=value and field!=value and choose the right one
- Configure a scheduled alert whose schedule, time range, delay and throttling avoid gaps, duplicates and floods
- Explain how roles and capabilities control what users can do, and why capabilities are additive
Course outline
- 1.Splunk: data, searching and alertsVideo · 2 min
- 2.How data gets into SplunkLesson · 15 min
- 3.Searching with SPLLesson · 18 min
- 4.Alerts, knowledge objects and accessLesson · 17 min
- 5.Splunk: data, searching and alerts for security monitoring: knowledge checkKnowledge check · 17 questions
- 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Splunk Enterprise Distributed Deployment Manual: Scale your deployment with Splunk Enterprise components
- Splunk Enterprise Forwarding Data: Types of forwarders
- Splunk Enterprise Getting Data In: About default fields (host, source, sourcetype, and more)
- Splunk Enterprise Managing Indexers: About managing indexes
- Splunk Enterprise Managing Indexers: Set a retirement and archiving policy
- Splunk Enterprise Search Manual: Quick tips for optimization
- Splunk Enterprise Search Manual: Use fields to retrieve events (NOT versus !=)
- Splunk Enterprise Search Reference: Time modifiers
- Splunk Enterprise Search Reference: stats
- Splunk Enterprise Search Reference: timechart
- Splunk Enterprise Search Reference: top
- Splunk Enterprise Search Reference: sort
- Splunk Enterprise Search Reference: dedup
- Splunk Enterprise Search Reference: where
- Splunk Enterprise Search Reference: rex
And 7 more.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.