Splunk Enterprise Architecture
- Indexers
- Search Heads
- Heavy Forwarders
- Universal Forwarders
- Parsing pipelines
- Indexing pipelines
Security Dashboards & Use Cases
- Authentication monitoring
- Privilege-escalation monitoring
- Endpoint monitoring
- Threat-activity dashboards
- Executive security dashboards
- Threat-hunting dashboards
Advanced Log Onboarding
- Windows Event Logs
- Sysmon integration
- Linux logs
- AWS CloudTrail
- AWS VPC Flow Logs
- Custom log parsing & sourcetypes
- Index design strategy
- Field extractions
- props.conf & transforms.conf
- CIM normalization & data models
Advanced SPL & Performance
- stats, eventstats, streamstats
- transaction, rex, regex, eval
- lookup, join, append, mvexpand
- bin, chart, timechart, tstats
- Accelerated data models
- Query optimization & summary indexing
- Search acceleration & data retention