Splunk On-Call Administration (SOCA) – Details

Detaillierter Kursinhalt

Module 1 – Getting Started with Users and Teams

  • Describe What Splunk On-Call is
  • Describe the flow of an alert/ incident in Splunk On-Call
  • Create a plan for incident response
  • Describe the layout of the On-Call User Interface
  • Create new users and teams
  • Create user paging (notification) policies
  • Create new Teams
  • Add users to teams

Module 2 – Incident Response Through Team Rotations and Escalation Policies

  • Create on-call schedules
    • Add rotations
    • Add shifts
    • Add members
  • Build escalation policies to handle incidents

Module 3 – Alert Rules Engine

  • Create Routing Keys to direct incoming alerts
  • Use the Alert Rule Engine to create alert rules
  • Use the Alert Rule Engine to transform fields

Module 4 – Integrations

  • Select appropriate external Monitoring System integrations
  • Configure common Splunk On-Call integrations

Module 5 – Reporting on Team Activity and Performance

  • Differentiate between the types of reports
  • Create a post-incident review report
  • Track response metrics
  • Customize on-call Review report
  • Track flow of incidents using the Incident Frequency report (Enterprise edition only)

Module 6 – (optional) Advanced Features

  • Use Terraform to manage On-Call
  • Use Maintenance Mode
  • Use Conference Bridge
  • Use Alert Configurations