Search Under the Hood

Course code: SPLUNKSUTH

This eLearning course gives students additional insight into how Splunk processes searches. Students will learn about Splunk architecture, how components of a search are broken down and distributed across the pipeline, and how to troubleshoot searches when results are not returning as expected.

and certified lecturers

recognized certifications

Wide range of technical
and soft skills courses

Great customer

Making courses
exactly to measure your needs

Course dates

Starting date: Upon request

Type: E-learning

Course duration: 1 hour

Language: en

Price without VAT: 0 EUR


Type Course
Language Price without VAT
Upon request E-learning 1 hour en 0 EUR Register
G Guaranteed course

Didn't find a suitable date?

Write to us about listing an alternative tailor-made date.


Course structure

Topic 1 – Investigating Searches

  • Use the Search Job Inspector to examine how a search was processed and troubleshoot performance
  • Use SPL commenting to help identify and isolate problems

Topic 2 – Splunk Architecture

  • Understand the role of search heads, indexers, and forwarders in a Splunk deployment
  • Understand how the components of a bucket (.tsidx and journal.gz files) are used
  • Understand how bloom filters are used to improve search speed

Topic 3 – Streaming and Non-Streaming Commands

  • Describe the parts of a search string
  • Understand the use of centralized vs. distributable commands
  • Create more efficient searches

Topic 4 – Breakers and Segmentation

  • Understand how segmenters are used in Splunk
  • Use lispy to reduce the number of events read from disk

Topic 5 – Commands and Functions for Troubleshooting

  • Using the fieldsummary command
  • Using the makeresults command
  • Using information functions with the eval command
    • the isnull function
    • the typeof function



  • Intro to Splunk eLearning course

Do you need advice or a tailor-made course?


product support

ComGate payment gateway MasterCard Logo Visa logo