Course Overview

This 13.5-hour course prepares security practitioners to use Splunk Enterprise Security (ES). Students identify and track incidents, analyze security risks, use predictive analytics, and discover threats.

What are the skills covered

  • ES concepts, features, and capabilities
  • Security monitoring and Incident investigation
  • Using risk-based alerting and risk analysis
  • Assets and identities overview
  • Creating investigations and using the Investigation Workbench
  • Detecting known types of threats
  • Monitoring for new types of threats
  • Using analytical tools and dashboards
  • Analyze user behavior for insider threats
  • Use threat intelligence tools

Who should attend this course

  • SOC Analysts

Course Curriculum

What are the Prerequisites

To be successful, students should have a working understanding of the topics covered in the following Splunk courses:

  • Intro to Splunk
  • Using Fields
  • Visualizations
  • Search Under the Hood
  • Intro to Knowledge Objects
  • Introduction to Dashboards

Download Syllabus

Course Modules

Request More Information

Training Options

Intake: 2-4 Feb 2026
Duration: 3 Days
Guaranteed: TBC
Modality: VILT
Price:

RM7,050.00Enroll Now

Exam:
[yith_ywraq_button_quote product="143066"]
Intake: 25-27 Feb 2026
Duration: 3 Days
Guaranteed: TBC
Modality: VILT
Price:

RM7,050.00Enroll Now

Exam:
[yith_ywraq_button_quote product="143067"]
Intake: 16-18 Mar 2026
Duration: 3 Days
Guaranteed: TBC
Modality: VILT
Price:

RM7,050.00Enroll Now

Exam:
[yith_ywraq_button_quote product="143068"]
Intake: 30 Mar - 1 Apr 2026
Duration: 3 Days
Guaranteed: TBC
Modality: VILT
Price:

RM7,050.00Enroll Now

Exam:
[yith_ywraq_button_quote product="143069"]
Intake: 15-17 Apr 2026
Duration: 3 Days
Guaranteed: TBC
Modality: VILT
Price:

RM7,050.00Enroll Now

Exam:
[yith_ywraq_button_quote product="143070"]

Exam & Certification

This course is not associated with any Certification.

Training & Certification Guide

Frequently Asked Questions