VIRTUAL

EMEA Virtual Workshops

Tuesdays – Thursdays | 10.00AM BST / 11.00AM CEST

Build practical Splunk skills in a live, guided lab

Learn by doing with Splunk experts. Hands-On Workshops are live virtual sessions that help you build practical skills through guided exercises, realistic scenarios, and hands-on work in a Splunk environment.

Choose from beginner, intermediate, and advanced topics across Splunk Platform, Security, Observability, dashboards, and AI resilience. Register for the session that fits your current experience, or select more than one to create your own learning path.

Sessions are start at 10.00 AM BST/11.00 AM CEST and vary between 3 and 4 hours in length.

What to expect?

  • Three to four hours of live, interactive instruction.
  • A hosted Splunk environment for guided exercises, where applicable.
  • Opportunities to learn from Splunk subject matter experts and other practitioners.
  • Practical skills and workflows you can carry into your own environment.
What you’ll need?
  • A computer or laptop with reliable internet access that can access external websites including Webex Webinars.
  • A splunk.com account to access the workshop environment (create an account here).
  • We recommend two monitors, or a second device, so you can follow the instructor while working in the lab, but these are not required.

Review the session descriptions below, choose your preferred date from the registration options, and reserve your place. These workshops are designed as hands-on taster sessions. Looking for official Splunk training? You can find more here.

Workshop Topics

Beginner Workshops

Workshop Title Topic and Level Details
Splunk4Rookies (3 hours) Platform | Beginner Go from Splunk Zero to Hero in 3 hours! Discover the value of Splunk hands-on in a matter of hours…
Learn more
Get hands-on with the Splunk platform in a supportive, guided environment. Through practical exercises, you will ingest data, create a Splunk app, run searches, and build an interactive dashboard. Along the way, you will explore how the same core platform supports use cases across IT operations, Security, DevOps, and business analytics.

What you’ll learn

  • Ingest and explore data in Splunk
  • Create an app and build useful searches
  • Turn results into an interactive dashboard
Target Audience

Sessions are designed for Splunk beginners. Whether your organisation is just starting to consider using Splunk or you have just joined a team of Splunk users and need to understand the basics, Splunk4Rookies is for you!
Splunk4Rookies - Dashboard Studios (3 hours) Platform | Beginner Discover Splunk Dashboard Studio, along with hands-on experience creating a dashboard based on multiple use cases…
Learn more
Attendees get an introduction to Splunk Dashboard Studio and learn how to create clear, interactive data experiences in Dashboard Studio. You will build effective searches, configure foundational interactions, and apply practical design principles to create a functional dashboard from the ground up. The workshop focuses on turning results into a story users can understand and explore.

What you’ll learn

  • Create searches that support dashboard use cases
  • Add useful interactions and visual structure
  • Build a complete Dashboard Studio experience

Target Audience

Sessions are designed for individuals early in their Splunk journey. It is recommended that participants either attend a core Splunk4Rookies workshop first or have a small amount of previous Splunk experience.
Splunk4Rookies – Observability (3 hours) Observability | Beginner Experience an issue and discover how you can use Splunk Observability Cloud to troubleshoot and identify the root cause…
Learn more
Get hands-on with Splunk Observability Cloud and learn how modern teams use metrics, traces, and logs to understand application and infrastructure health. In a guided troubleshooting scenario, you will work with real-time telemetry generated from browser sessions, visualize performance, and identify the source of issues across digital experiences.

What you’ll learn

  • Ingest and explore observability data
  • Monitor applications and infrastructure in real time
  • Use telemetry to investigate performance issues

Target Audience

The workshop is designed for DevOps and Site-Reliability Engineers, plus anyone else wanting to gain an understanding of Splunk Observability Cloud using a hands-on environment. This workshop is designed for people with little or no experience with Splunk Observability.
Investigating with Splunk (4 hours) Security | Beginner Gain experience searching in Splunk to answer specific questions related to an investigation…
Learn more
This workshop provides users a way to gain experience searching in Splunk to answer specific questions related to an investigation. Users will leave with a better understanding of how Splunk can be used to investigate in their enterprise.

Target Audience

This workshop is ideal for individuals who are new to Splunk and are part of a Security Operations team responsible for security monitoring and incident response.

Deep Dive Workshops

Workshop Title Topic and Level Details
Enterprise Security 8 (4 hours) Security | Intermediate Explore how Splunk, Enterprise Security, and SOAR can be used to generate findings and investigate them as they occur…
Learn more
Go deeper into Splunk Enterprise Security 8 through a realistic analyst workflow. You will navigate the redesigned experience, manage notable events, author detections, and investigate adversary activity with and without automation. The lab follows the incident lifecycle from initial detection through investigation and response, including integrated SOAR capabilities.

What you’ll learn

  • Navigate the Enterprise Security 8 analyst workflow
  • Create and manage detections and notable events
  • Investigate incidents and apply automation where it adds value

Target Audience

This workshop is ideal for individuals who are already familiar with Splunk and are on a Security Operations team responsible for threat detection and incident response.
Splunk Data Management (4 hours) Platform | Intermediate Uncover how Splunk Data Management puts flexibility and control in your hands to accelerate your data and security…
Learn more
Discover how Splunk Data Management puts flexibility and control in your hands to accelerate your data and security projects.

This workshop will allow you to discover all the possibilities offered by Ingest Actions (IA), Edge Processor (EP), and Ingest Processor (IP), and how these features enable you to quickly manage your data as it's transmitted to Splunk. You'll learn how to use these tools from a web browser and how to filter, mask, transform, enrich, and route your data to multiple destinations.

Target Audience

  • DevOps and SecOps engineers looking to optimize their observability pipelines.
  • IT and data leaders wanting to control costs and compliance.
  • System architects involved in cloud/edge modernization projects.


Splunk for AI Resilience (3 hours) Platform | Intermediate Bridge the gap between cutting-edge AI innovation and your core data platform…
Learn more
The AI revolution is here, but are you ready to operationalize it? This session explores AI from both sides of the resilience challenge: using AI to accelerate work in Splunk and using Splunk to monitor and secure AI-powered systems. In guided exercises, you will build Model Context Protocol connections, use AI assistance to accelerate SPL development, and examine the operational and security practices required for responsible AI deployment.

What you’ll learn

  • Connect AI tools and Splunk through MCP
  • Use AI assistance to accelerate SPL workflows
  • Apply observability and security thinking to AI workloads

Target Audience

This workshop is ideal for IT and security analysts who have a solid handle on Splunk and are ready to bridge the gap between AI curiosity and real-world, enterprise-grade application.
Splunk4Ninjas – SPL Best Practices (3 hours) Platform | Intermediate/Advanced Discover tips & tricks, best practices and practical examples on how to improve your SPL…
Learn more
SPL best practices sessions are a great opportunity for you to deepen your existing Splunk skills in a matter of hours. Attendees benefit from lots of useful information including tips & tricks, best practices and practical examples on how to improve their SPL in our hands-on lab environment.

During the session, we will show you how to write better and efficient searches. We’ll share some useful tips & tricks, deal with complex data sets, different commands, macros, multi-value fields, regex and we will provide you with useful resources at the end of the session as well as cover Q&A.

Target Audience

Sessions are designed for experienced Splunk users looking to take their skills to the next level.