Using Splunk Log Observer Connect (USLO)


Course Content

This course is designed for developers responsible for debugging their own applications, and for SREs responsible for troubleshooting performance issues. Splunk Log Observer Connect is built primarily for DevOps teams working on applications built on modern tech stacks (containerized microservices) and who need to explore logs from Splunk Cloud Platform or Splunk Enterprise in Splunk Observability Cloud. However, the course can be taken by anyone who wants to view recent log data in a no-code environment.

This 3-hour course describes how to use the tool to work with log data using the no-code user interface. Learn to create, save, and share search filters, and to investigate Splunk Cloud/Enterprise logs in context with correlated metrics and traces. Learn to add log messages to dashboards. Analyze logs with aggregation functions and group by rules.

All concepts are taught using lectures and scenario-based hands-on activities


  • Introduction to Splunk Observability (eLearning)
  • Introduction to Splunk Log Observer Connect (eLearning)
  • Basic knowledge of navigating and visualizing metrics in Splunk Observability Cloud

Course Objectives

  • View log data
  • Describe how log data is parsed and structured in the tool
  • Create filters for log data; save and reuse these filters
  • Investigate the shape of log data with Log Observer Connect
  • Analyze data with aggregation functions and group by rules
  • Describe Log Observer Connect setup

Outline: Using Splunk Log Observer Connect (USLO)

Module 1 – Explore Splunk Log Observer Connect

  • Determine how to navigate between types of telemetry data
  • Define the term "no-code search"
  • Describe some use cases for the Log Observer Connect

Module 2 – Log Observer Connect Basics

  • View trends in logs over time
  • Use an aggregation function to summarize log data
  • Browse fields and top values for logs
  • Create a set of filters from field data
  • Save filter sets
  • Change the time range for logs displayed
  • Describe the relationship between the four parts of the user Interface

Module 3 – Advanced Searching

  • Add multiple search filters using field values and keywords
  • Create and tag Saved Queries
  • Create log views
  • Create visualizations from aggregate log data
  • Save logs to dashboards
  • Segment visualization using Group by
  • Restrict time windows for viewing log data in various ways

Module 4 - Set up Log Observer Connect

  • Get data from the Splunk platform
  • Explain field types in Log Observer Connect
  • Name some of the ways that log data is enriched
  • Differentiate between log messages and metadata

Prices & Delivery methods

Online Training

3 hours

  • Online Training: CAD 635
  • Online Training: US$ 500
  • Splunk Training Units: 50 SPC
Classroom Training

3 hours

  • Canada: CAD 635
  • Splunk Training Units: 50 SPC

Click on town name or "Online Training" to book Schedule

This is an Instructor-Led Classroom course
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.


Online Training Time zone: Europe/Berlin Enroll