Course Overview
This 13.5-hour course prepares security practitioners to use Splunk Enterprise Security (ES). Students identify and track incidents, analyze security risks, use predictive analytics, and discover threats.
What are the skills covered
- ES concepts, features, and capabilities
- Security monitoring and Incident investigation
- Using risk-based alerting and risk analysis
- Assets and identities overview
- Creating investigations and using the Investigation Workbench
- Detecting known types of threats
- Monitoring for new types of threats
- Using analytical tools and dashboards
- Analyze user behavior for insider threats
- Use threat intelligence tools
Who should attend this course
- SOC Analysts
Course Curriculum
What are the Prerequisites
To be successful, students should have a working understanding of the topics covered in the following Splunk courses:
- Intro to Splunk
- Using Fields
- Visualizations
- Search Under the Hood
- Intro to Knowledge Objects
- Introduction to Dashboards
Download Course Syllabus
Course Modules
- Explain the function of a SIEM
- Give an overview of Splunk Enterprise Security (ES)
- Understand how ES uses data models
- Describe detections and findings
- Identify ES roles and permissions
- Give an overview of ES navigation
- Explore the Analyst Queue
- Filtering
- Triage Findings and Finding Groups
- Create ad hoc Findings
- Suppress Findings from the Analyst Queue
- Give an overview of an investigation
- Demonstrate how to create an investigation
- Use Response Plans
- Add Splunk events to an investigation
- Use Playbooks and Actions
- Give an overview of risk and Risk-Based Alerting (RBA)
- Explain risk scores and how to change an entity’s risk score
- Review the Risk Analysis dashboard
- Describe annotations
- View risk information in Analyst Queue findings
- Give an overview of the ES Assets and Identities (A&I) framework
- Show where asset or identity data is missing from ES findings or dashboards
- View the A&I Management Interface
- View the contents of an asset or identity lookup table
- Identify A&I field matching criteria
- Describe Adaptive Responses
- Identify the default ES Adaptive Responses
- Discuss Adaptive Response invocation methods
- Troubleshoot Adaptive Response issues
- Use ES to inspect events containing information relevant to active or past incident investigation
- Identify ES Security Domains
- Use the Security Domain dashboards
- Launch Security Domain dashboards from the Analyst Queue and from field action menus in search results
- Use the Web Intelligence dashboards to analyze your network environment
- Filter and highlight events
- Understand and use User Intelligence dashboards
- Use Investigators to analyze events related to an asset or identity
- Use Access Anomalies to detect suspicious access patterns
- Give an overview of the Threat Intelligence framework
- Identify where Threat Intelligence is configured
- Observe Threat Findings
- View downloaded Threat Indicators
- Troubleshooting Threat Intelligence
- Explain how network data is input into Splunk events
- Describe stream events
- Give an overview of the Protocol Intelligence dashboards and how they can be used to analyze network data
Request More Information
Training Options
- VILT: Virtual Instructor-Led Training
RM7,050.00Enroll Now
RM7,050.00Enroll Now
RM7,050.00Enroll Now
RM7,050.00Enroll Now
RM7,050.00Enroll Now
Exam & Certification
This course is not associated with any Certification.
Training & Certification Guide
Frequently Asked Questions
Splunk is a powerful tool for analyzing and visualizing data from a variety of sources, including log files, application data, and network traffic. It can be used to troubleshoot issues, detect security threats, and gain insights into the performance and usage of systems and applications.
There are several reasons why learning Splunk might be beneficial:
- Demand for Splunk skills is high: Splunk is widely used in a variety of industries, and there is a high demand for professionals with Splunk skills
- Splunk can be used to solve complex problems: Splunk’s advanced search and analysis capabilities allow you to quickly identify and resolve issues, which can save time and resources
- Splunk can improve efficiency: Splunk allows you to automate the collection, analysis, and visualization of data, which can improve the efficiency of your operations
- Splunk is a valuable tool for data professionals: If you work in data analytics or data science, learning Splunk can help you extract insights and value from large datasets
Splunk has a strong ecosystem: Splunk has a large and active community of users, as well as a rich ecosystem of partners and integrations, which makes it easy to find resources and support when using the tool.
Splunk is a powerful tool that is widely used in a variety of industries, and there is a high demand for professionals with Splunk skills.
Splunk is particularly useful for log management, security analytics, and operational intelligence, and it can be used to troubleshoot issues, detect security threats, and gain insights into the performance and usage of systems and applications.
If you work in IT, data analytics, or a related field, learning Splunk can be a valuable addition to your skill set and may open up new job opportunities. Splunk is also a useful tool for data professionals, such as data analysts and data scientists, as it allows you to extract insights and value from large datasets.
Splunk offers a range of certification designed for different areas of expertise and obtaining a Splunk certification is a valuable way to demonstrate your knowledge and expertise with the Splunk platform to potential employers and clients.
Benefits of obtaining a Splunk certification include:
Increased credibility: A Splunk certification can serve as a third-party endorsement of your knowledge and skills, which can help to increase your credibility and differentiate you from other professionals in the field.
Career advancement: Employers often look for candidates with proven expertise and experience, and a Splunk certification can demonstrate to potential employers that you have the skills and knowledge necessary to excel in your role.
Improved job prospects: Having a Splunk certification can make you a more competitive candidate for job openings that require Splunk skills, and it may also help you to negotiate higher salaries and benefits.
Professional development: Obtaining a Splunk certification can help you to stay up-to-date with the latest features and best practices in the field, and it can also provide a sense of accomplishment and personal development.
To put it plainly: Splunk Certification pays. Candidates who are Splunk Certified earn an average of 16% more than their uncertified peers. Organizations who invest in Splunk Certification earn faster time to value and are more likely to renew and expand their license.





