Splunk SPLK-2001 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|
| トピック 1 | - Creating a KV Store
- Define What is a KV Store
- Describe KV Store Lookup
|
| トピック 2 | - Use Event Handlers
- Identify Types of Event Handlers
- Describe Event Actions
|
| トピック 3 | - Add Advanced Visualizations & Behaviors
- Describe Simple XML Extensions
- Describe Splunk Custom Visualizations
|
| トピック 4 | - Describe the REST URI Format
- Identify Which Splunk Server to Connect to (e.g., search head, indexer, forwarder)
- Identify Where REST Logging Occurs
|
| トピック 5 | - Packaging Apps
- Describe the Difference Between Local and Default Directories
- Introduction to the Splunk REST API
|
| トピック 6 | - Use Forms: Explain How Tokens Work
- Define Types of Token Filters
|
| トピック 7 | - Searching, Describe the Importance of Specifying Fields in a Search, Describe Options for Specifying a Search Time Range, Describe Blocking, Oneshot, Normal, and Export Searches
|
| トピック 8 | - Describe HEC Tokens and How They are Used
- Describe Indexer Acknowledgement
- Create and Use HEC Tokens to Get Data into Splunk
|
| トピック 9 | - Improve Performance: Use the Tstats Command
- Use Global Searches
|
| トピック 10 | - Creating Apps, Define the App Directory Structure
- Describe App Permissions
|
| トピック 11 | - Describe Access Control Lists
- Update Access Control Lists
- Parsing REST Output
|
| トピック 12 | - Add Drilldowns
- Define Types of Drilldowns
- Identify Predefined Tokens
|
| トピック 13 | - Create and Manage Search Jobs
- Describe Ways to Improve Search Performance
- Writing Data to Splunk
|
| トピック 14 | - Planning App Development
- Describe Ways to Monitor App Performance
- Identify Useful Splunk Log Files
- Describe Security Best Practices
|
参照:https://www.splunk.com/pdfs/training/Splunk-Test-Blueprint-Developer-v.1.1.pdf
Splunk SPLK-2001 試験概要: