Current resource map

Use official material first, then layer practice on top.

This page groups the most useful official Splunk learning and documentation resources, then shows where practice environments and datasets fit. The structure here is based on current official pages checked on June 18, 2026.

Official training

Where to start inside Splunk's own learning ecosystem

Fundamentals sequence

Splunk explicitly recommends starting beginners with the fundamentals sequence before deeper work.

Open Splunk Fundamentals

Course catalog

Use this when you want to browse beyond the first free steps into role, product, and exam preparation paths.

Open Course Catalog

Path selection

Choose by role or by certification, not by random tutorial order

Learning paths by role

Splunk maintains role-based paths for people such as search experts, knowledge managers, data science analysts, security practitioners, and administrators.

Open Role-Based Learning Paths

All learning paths

The broader learning path landing page says there are more than 15 role-based paths and also product-based paths.

Open All Learning Paths

Certification overview

This is the high-level certification page, including current credential families and exam direction.

Open Splunk Certifications

Documentation

Most useful documentation starting points

Documentation portal

The main docs landing page points new users to the Search Tutorial and product documentation.

Open Splunk Documentation

Search reference

Use this when you want precise syntax and command behavior rather than introductory flow.

Open Search Reference

Working with fields

Fields are one of the most important concepts in effective SPL work, and Splunk's tutorial explicitly calls them out.

Open Tutorial: Use Fields to Search

Practice resources

Practice environments and datasets that matter

Boss of the SOC portal

BOTS is one of the most recognizable hands-on blue-team practice environments associated with Splunk learning.

Open BOTS Portal

BOTS v3 dataset repository

The open repository provides a practical starting point for investigation-oriented learning.

Open BOTS v3 Repository

Why BOTS matters

Splunk describes BOTS as a blue-team, jeopardy-style investigation challenge built around realistic security incidents.

Read the BOTS explainer

Recent BOTS context

Splunk continued promoting BOTS events in 2026, which is a useful sign that the model remains relevant as a practice format.

Read 2026 BOTS GovSummit post

How to use this

Recommended sequence by learner type

For non-tech learners

  • Start with free courses and fundamentals.
  • Use the glossary on this site while reading the docs.
  • Focus on dashboards, alerts, fields, and use-case language before deep SPL.
  • Move into role maps and playbooks once the vocabulary is stable.

For tech learners

  • Start with fundamentals, then jump quickly into search tutorial and field usage.
  • Choose a role-based or certification path to avoid random topic hopping.
  • Use labs and BOTS-style investigation practice to produce evidence of skill.
  • Treat the docs and reference manuals as working tools, not background reading.