Explore Courses

Splunk Architect Master's

Intellipaat offers Splunk online classes that includes Splunk developer, administration and SIEM components. This Splunk Architect master's program helps you learn Splunk search and search commands, report creation, analyzing data with Splunk visualization, data management, deploying Splunk SIEM for investigating and monitoring security solutions.

Key Features

  • Instructor Led Training : 46 Hrs
  • Exercises & Project Work : 80 Hrs
  • Certification and Job Assistance
  • Flexible Schedule
  • Lifetime free upgrade
  • 24 x 7 Lifetime Support & Access

About Splunk Architect Master's Program Course

Intellipaat Splunk Architect master's program has been created by industry experts to give you 360-degree training in Splunk. As part of this course, you will learn Splunk development and administration, along with Splunk Security Intelligence and Enterprise Management (SIEM). This training includes searching, indexing, building reports, configuring the Splunk solution, detecting and investigating threats to create a security framework with Splunk SIEM.

What will you learn in this Splunk master's program?

  1. Introduction to Splunk architecture and enterprise security
  2. Deploying Splunk visualization and data analytics
  3. Managing and monitoring Splunk users and indexes
  4. Splunk log analyzer, database lookup and execution
  5. Investigating and monitoring events with Splunk SIEM
  6. Deploying Splunk SIEM for security and forensics
  7. Creating a framework and validating a security model

Who should take up this Splunk Architect online training course?

Software Developers, System Administrators, Search Analysts, Security Professionals, Database Administrators and others.

What are the prerequisites for taking up this training course?

There are no prerequisites for taking up this training. The only requirement is that you need to first complete the Splunk developer and administration domains and then learn the Splunk SIEM.

Why should you take up this Splunk master's program?

Splunk is the most popular tool for working with machine data. Splunk is also extensively used for security monitoring, analysis and threat mitigation. Intellipaat Splunk master’s program has been created to help you be a complete Splunk professional. Once you learn the Splunk developer and administration domains, you can be qualified to learn the Splunk SIEM domain. Upon the completion of the training, your skills will be highly demanded by the industry helping you fast-track your career.

view more
Read Less

Splunk Architect Master’s Program Course Content

Splunk Developer Course Content

Splunk Development Concepts

Introduction to Splunk and Splunk developer roles and responsibilities

Basic Searching

Writing Splunk query for search, auto-complete to build a search, time range, refine search, working with events, identifying the contents of search and controlling a search job

Hands-on Exercise – Write a basic search query

Using Fields in Searches

What is a Field, how to use Fields in search, deploying Fields Sidebar and Field Extractor for REGEX field extraction and delimiting Field Extraction using FX

Hands-on Exercise – Use Fields in Search, use Fields Sidebar, use Field Extractor (FX) and delimit field Extraction using FX

Saving and Scheduling Searches

Writing Splunk query for search, sharing, saving, scheduling and exporting search results

Hands-on Exercise – Schedule a search, save a search result and share and export a search result

Creating Alerts

How to create alerts, understanding alerts and viewing fired alerts.

Hands-on Exercise –Create an alert in Splunk and view the fired alerts

Scheduled Reports

Describe and configure scheduled reports

Tags and Event Types

Introduction to Tags in Splunk, deploying Tags for Splunk search, understanding event types and utility and generating and implementing event types in search

Hands-on Exercise – Deploy tags for Splunk search and generate and implement event types in search

Creating and Using Macros

What is a Macro and what are variables and arguments in Macros

Hands-on Exercise –First, you define a Macro with arguments and then use variables with in it


Creating get, post and search workflow actions

Hands-on Exercise – Create get, post and search workflow actions

Splunk Search Commands

Studying the search command, the general search practices, what is a search pipeline, how to specify indexes in search, highlighting the syntax and deploying the various search commands like fields, tables, sort, rename, rex and erex

Hands-on Exercise –Steps to create a search pipeline, search index specification, how to highlight syntax, using the auto complete feature and deploying the various search commands like sort, fields, tables, rename, rex and erex

Transforming Commands

Using top, rare and stats commands

Hands-on Exercise – Use top, rare and stats commands

Reporting Commands

Using following commands and their functions: addcoltotals, addtotals,top, rare and stats

Hands-on Exercise – Create reports using following commands and their functions: addcoltotals and addtotals

Mapping and Single Value Commands

iplocation, geostats, geom and addtotals commands

Hands-on Exercise – Track IP using iplocation and get geo data using geostats

Splunk Reports and Visualizations

Explore the available visualizations, create charts and time charts, omit null values and format results

Hands-on Exercise – Create time charts, omit null values and format results

Analyzing, Calculating and Formatting Results

Calculating and analyzing results, value conversion, roundoff and format values, using the eval command, conditional statements and filtering calculated search results

Hands-on Exercise – Calculate and analyze results, perform conversion on a data value, roundoff numbers, use the eval command, write conditional statements and apply filters on calculated search results

Correlating Events

How to search the transactions, creating report on transactions, grouping events using time and fields and comparing transactions with stats

Hands-on Exercise – Generate report on transactions and group events using fields and time

Enriching Data with Lookups

Learning data lookups, examples and lookup tables, defining and configuring automatic lookups and deploying lookups in reports and searches

Hands-on Exercise – Define and configure automatic lookups and deploy lookups in reports and searches

Creating Reports and Dashboards

Creating search charts, reports and dashboards, editing reports and dashboards and adding reports to dashboards

Hands-on Exercise – Create search charts, reports and dashboards, edit reports and dashboards andadd reports to dashboards

Getting Started with Parsing

Working with raw data for data extraction, transformation, parsing and preview

Hands-on Exercise – Extract useful data from raw data, perform transformation and parse different values and preview

Using Pivot

Describe pivot, relationship between data model and pivot, select a data model object, create a pivot report, create in stant pivot from a search and add a pivot report to dashboard

Hands-on Exercise – Select a data model object, create a pivot report, create instant pivot from a search and add a pivot report to dashboard

Common Information Model (CIM) Add-On

What is a Splunk CIM and using the CIM Add-On to normalize data

Hands-on Exercise – Use the CIM Add-On to normalize data

Splunk Administration Topics

Overview of Splunk

Introduction to the architecture of Splunk, various server settings, how to set up alerts, various types of licenses, important features of Splunk tool, the requirements of hardware and conditions needed for installation of Splunk

Splunk Installation

How to install and configure Splunk, the creation of index, standalone server’s input configuration, the preferences for search, Linux environment Splunk installation and the administering and architecting of Splunk

Splunk Installation in Linux

How to install Splunk in the Linux environment, the conditions needed for Splunk and configuring Splunk in the Linux environment

Distributed Management Console

Introducing Splunk distributed management console, indexing of clusters,how to deploy distributed search in Splunk environment, forwarder management, user authentication and access control

Introduction to Splunk App

Introduction to the Splunk app, how to develop Splunk apps, Splunk app management, Splunk app add-ons, using Splunk-base for installation and deletion of apps, different app permissions and implementation and how to use the Splunk app and apps on forwarder

Splunk Indexes and Users

Details of the index time configuration file and the search time configuration file

Splunk Configuration Files

Understanding of Index time and search time configuration filesin Splunk, forwarder installation, input and output configuration, Universal Forwarder management and Splunk Universal Forwarder highlights

Splunk Deployment Management

Implementing the Splunk tool, deploying it on the server, Splunk environment setup and Splunk client group deployment

Splunk Indexes

Understanding the Splunk Indexes, the default Splunk Indexes, segregating the Splunk Indexes, learning Splunk Buckets and Bucket Classification, estimating Index storage and creating new Index

User Roles and Authentication

Understanding the concept of role inheritance, Splunk authentications, native authentications and LDAP authentications

Splunk Administration Environment

Splunk installation, configuration, data inputs, app management, Splunk important concepts, parsing machine-generated data, search indexer and forwarder

Basic Production Environment

Introduction to Splunk Configuration Files, Universal Forwarder, Forwarder Management, data management, troubleshooting and monitoring

Splunk Search Engine

Converting machine-generated data into operational intelligence, setting up the dashboard, reports and charts and integrating Search Head Clustering and Indexer Clustering

Various Splunk Input Methods

Understanding the input methods, deploying scripted, Windows and network and agentless input types and fine-tuning them all

Splunk User and Index Management

Splunk user authentication and job role assignment and learning to manage, monitor and optimize Splunk Indexes

Machine Data Parsing

Understanding parsing of machine-generated data, manipulation of raw data, previewing and parsing, data field extraction and comparing single-line and multi-line events

Search Scaling and Monitoring

Distributed search concepts, improving search performance, large-scale deployment and overcoming execution hurdles and working with Splunk Distributed Management Console for monitoring the entire operation

Splunk Cluster Implementation

Cluster indexing, configuring individual nodes, configuring the cluster behavior, index and search behavior, setting node type to handle different aspects of cluster like master node, peer node and search head

Splunk SIEM Course Content

Introduction to Splunk Security

Understanding the fundamentals of Splunk security, details of the traditional security threats, describing correlation searches and what is a security data model

Investigation and Monitoring

How to monitor the dashboard and brief on each panel, investigating notable events with incident review dashboards, workflow investigation and relative action on identified flow


Deploying ES investigation timelines for managing, visualizing and coordinating incident investigations and using journals and timelines for documenting breach analysis and efforts needed to mitigate the issues

Risk and Network Analysis

Deploying risk analysis and identification, risk dashboard utilization and how to manage the risk scores for objects and users

Web Intelligence

Using HTTP category analysis, HTTP user agent analysis, analyzing new domain, analyzing traffic size for spotting new threats and highlighting investigable events

User Intelligence

Accessing the anomaly dashboards for user role and access logs and understanding the identity and asset concepts

Threat Intelligence

Monitoring the malicious sites with threat activity dashboard and inspecting threat intelligence content with threat artifact dashboard

view more
Read Less

Splunk Architect Master’s Program Projects

What projects I will be working on this Splunk Developer and Admin training?

Project 1 : Creating an Employee Database of a Company

Industry : General

Problem Statement : How to build a Splunk dashboard where employee details are readily available

Topics : In this project, you will create a text file of employee data with details like full name, salary, designation, ID and so on. You will index the data based on various parameters, use various Splunk commands for evaluating and extracting the information. Finally, you will create a dashboard and add various reports to it.

Highlights :

  • Splunk search and index commands
  • Extracting field in search and saving results
  • Editing event types and adding tags

Project 2 : Building an Organizational Dashboard with Splunk

Industry :  E-commerce

Problem Statement : How to analyze website traffic and gather insights

Topics :  In this project, you will build an analytics dashboard for a website and create alerts for various conditions. You will capture access logs of the web server andthe sample logs and them the sample are uploaded. You will analyze the top ten users, the average time spent, peak response time of the website, the top ten errors and error code description. You will also create a Splunk dashboard for reporting and analyzing.

Highlights :

  • Creating bar and line charts
  • Sending alerts for various conditions
  • Providing admin rights for dashboard

Project 3 : Field Extraction in Splunk

Industry : General

Problem Statement :How to extract the fields from event data in Splunk

Topics : In this project, you will learn to extract fields from events using the Splunk field extraction technique. You will gain knowledge in the basics of field extractions, understand the use of the field extractor, the field extraction page in Splunk web and field extract configuration in files. You will learn the regular expression and delimiters method of field extraction. Upon the completion of the project, you will gain expertise in building Splunk dashboard and use the extracted fields data in it to create rich visualizations in an enterprise setup.

Highlight :

  • Field extraction using delimiter method
  • Delimit field extracts using FX
  • Extracting fields with the search command

What projects I will be working on this Splunk SIEM training?

Project: A BPO Firm Wants to Secure Its Confidential Data

Industry: Outsourcing

Problem Statement:How to ensure that an outsourcing firm does not fall prey to IT security threats

Topics: In this project, you will work with the business process outsourcing firms’ machine-generated data to look for suspicious activities, anomalies and suspected threats. You will deploy the Splunk SIEM tool for combing through huge volumes of data and deploy Splunk analytics to come up with enterprise security reports and recommendations for securing the activity of the enterprise.

Highlights :

  • Deploy Splunk Enterprise Security
  • Investigate and monitor events
  • Enterprise security model validation
view more
Read Less Project

Sample Splunk Architect Master’s Program Video Tutorials

view more
View Less Sample Videos

Splunk Architect Certification

This training course is designed for clearing the following exams:

  • Splunk Certified Power User Certification
  • Splunk Certified Admin Certification
  • Splunk Certified Enterprise Security Admin

The entire course content is in line with the certification programs and helps you clear the certification exam with ease and get the best jobs in the top MNCs.

As part of this Splunk course, you will be working on real-time projects and assignments that have immense implications in the real-world industry scenarios, thus helping you fast track your career effortlessly.

At the end of this training program, there will be a quiz that perfectly reflects the type of questions asked in the certification exams and helps you score better marks.

Intellipaat Course Completion Certificate will be awarded upon the completion of the project work (after expert review) and upon scoring at least 60% marks in the quiz. Intellipaat certification is well recognized in top 80+ MNCs like Ericsson, Cisco, Cognizant, Sony, Mu Sigma, Saint-Gobain, Standard Chartered, TCS, Genpact, Hexaware, etc.

view more
Read Less Certification

Splunk Architect Reviews

view more
View Less Reviews Video
  1. Profile photo of chiragvenaik2601 Chirag Venaik 

    Well-versed Trainer

    I was guided step-by-step in each module by the trainer. He is extremely well-versed in his subject and is well-spoken also. He cleared my doubts and help me learn all that I expected. Great work Intellipaat!

  2. Profile photo of vikas.s VIKAS SAGAR 

    Great support from Intellipaat.

    The instructor had strong professional experience. I felt that this course is suitable for both basic level learners and for advanced learners. The support team resolved my doubts even after the course completion. I was really happy with the entire course, material, and support that Intellipaat has provided to me.

  3. Profile photo of akainettey Nii Akai 

    Excellent training.

    My overall training journey was good. The trainers were cooperative. All my questions were quickly answered with a detailed explanation. I have always received more than what I asked. Thanks a lot.

Frequently Asked Questions about Splunk Architect

Why should I take up Intellipaat Splunk Architect Master's Program?

Software trial version is available for 1 week. After that you just pay Rs.10K to get the software for lifetime.

Intellipaat Splunk Architect master’s program has been tailor-made to the specifications of the industry. Intellipaat Splunk course will give you hands-on experience in installing and configuring Splunk, deploying Splunk searches and indexes, creating reports, sorting, analysis, user administration, threat analysis, real-time monitoring and creating alerts with the Splunk tool.

You will be working on real-time projects that have high relevance in the corporate world and step-by-step assignments, and the curriculum is designed by industry experts. Upon the completion of the training course, you can apply for some of the best jobs in top MNCs around the world at top salaries. Intellipaat offers lifetime access to videos, course materials, 24/7 support and course material upgrading to the latest version at no extra fees. Hence, it is clearly a one-time investment.

What are the different modes of training that Intellipaat provides?
At Intellipaat you can enroll either for the instructor-led online training or self-paced training. Apart from this Intellipaat also offers corporate training for organizations to upskill their workforce. All trainers at Intellipaat have 12+ years of relevant industry experience and they have been actively working as consultants in the same domain making them subject matter experts. Go through the sample videos to check the quality of the trainers.
Can I request for a support session if I need to better understand the topics?
Intellipaat is offering the 24/7 query resolution and you can raise a ticket with the dedicated support team anytime. You can avail the email support for all your queries. In the event of your query not getting resolved through email we can also arrange one-to-one sessions with the trainers. You would be glad to know that you can contact Intellipaat support even after completion of the training. We also do not put a limit on the number of tickets you can raise when it comes to query resolution and doubt clearance.
Can you explain the benefits of the Intellipaat self-paced training?
Intellipaat offers the self-paced training to those who want to learn at their own pace. This training also affords you the benefit of query resolution through email, one-on-one sessions with trainers, round the clock support and access to the learning modules or LMS for lifetime. Also you get the latest version of the course material at no added cost. The Intellipaat self-paced training is 75% lesser priced compared to the online instructor-led training. If you face any problems while learning we can always arrange a virtual live class with the trainers as well.
What kind of projects are included as part of the training?
Intellipaat is offering you the most updated, relevant and high value real-world projects as part of the training program. This way you can implement the learning that you have acquired in a real-world industry setup. All training comes with multiple projects that thoroughly test your skills, learning and practical knowledge thus making you completely industry-ready. You will work on highly exciting projects in the domains of high technology, ecommerce, marketing, sales, networking, banking, insurance, etc. Upon successful completion of the projects your skills will be considered equal to six months of rigorous industry experience.
Does Intellipaat offer job assistance?
Intellipaat actively provides placement assistance to all learners who have successfully completed the training. For this we are exclusively tied-up with over 80 top MNCs from around the world. This way you can be placed in outstanding organizations like Sony, Ericsson, TCS, Mu Sigma, Standard Chartered, Cognizant, Cisco, among other equally great enterprises. We also help you with the job interview and résumé preparation part as well.
Is it possible to switch from self-paced training to instructor-led training?
You can definitely make the switch from self-paced to online instructor-led training by simply paying the extra amount and joining the next batch of the training which shall be notified to you specifically.
How are Intellipaat verified certificates awarded?
Once you complete the Intellipaat training program along with all the real-world projects, quizzes and assignments and upon scoring at least 60% marks in the qualifying exam; you will be awarded the Intellipaat verified certification. This certificate is very well recognized in Intellipaat affiliate organizations which include over 80 top MNCs from around the world which are also part of the Fortune 500 list of companies.
Will The Job Assistance Program Guarantee Me A Job?
In our Job Assistance program we will be helping you land in your dream job by sharing your resume to potential recruiters and assisting you with resume building, preparing you for interview questions. Intellipaat training should not be regarded either as a job placement service or as a guarantee for employment as the entire employment process will take part between the learner and the recruiter companies directly and the final selection is always dependent on the recruiter.
view more
Read Less FAQ
Lifetime Access and 24/7 Support
You have of $0 in your cart.
Online Classroom


Sat & Sun
8 PM IST (GMT +5:30)


Sat & Sun
8 PM IST (GMT +5:30)


Sat & Sun
8 PM IST (GMT +5:30)


Sat & Sun
8 PM IST (GMT +5:30)
Drop Us a Query

Call Us

Training in Cities: Bangalore, Hyderabad, Chennai, Delhi, Kolkata, UK, London, Chicago, San Francisco, Dallas, Washington, New York, Orlando, Boston

Select Currency

Sign Up or Login to view the Free Splunk Architect Master's Program course.