757-216-3656 | Monday–Friday 8:30 AM – 4:30 PM | info@itdojo.com

Course Duration

2 Days

Audience

Employees of federal, state and local governments; and businesses working with the government.

Prerequisites

Completion of Splunk Enterprise Administration (SP-ADM-FT or SP-SESA + SP-SEDA). Familiarity with Splunk Enterprise Security usage is recommended.

Course Description

This 13.5-hour course enables SOC engineers to configure and administer Splunk Enterprise Security for detection engineering and SIEM management. Students learn to configure ES data inputs, create and tune correlation searches, manage threat intelligence sources, configure risk-based alerting, and maintain ES health and performance.

Learning Objectives

  • Configure data inputs and data models required by Splunk Enterprise Security
  • Create, tune, and manage correlation searches for threat detection
  • Configure and manage threat intelligence sources and lookups
  • Implement and tune risk-based alerting rules
  • Manage notable event configuration and suppression
  • Configure glass tables and executive security dashboards
  • Monitor and maintain Splunk Enterprise Security health
  • Implement ES best practices for SOC operations

Course Outline

ES Architecture and Configuration
  • ES architecture overview
  • Data models and CIM compliance
  • Configuring ES data inputs
Correlation Search Management
  • Correlation search framework
  • Creating and editing correlation searches
  • Tuning false positives and suppression
Threat Intelligence Management
  • Threat intelligence framework
  • Configuring threat intelligence sources
  • Managing IOC lookups
Risk-Based Alerting Administration
  • Risk factor configuration
  • Risk scoring and aggregation
  • Tuning risk-based alerting rules
ES Maintenance
  • Monitoring ES health
  • Performance tuning
  • Notable event management

Frequently Asked Questions

What does Administering Splunk Enterprise Security cover?

This 2-day course covers the administrator side of Splunk ES -- configuring data inputs, creating and tuning correlation searches, managing threat intelligence, administering risk-based alerting, and maintaining ES performance.

Who should take this course?

This course is for SOC engineers and Splunk administrators who are responsible for configuring, maintaining, and tuning a Splunk Enterprise Security deployment.

Is Splunk administration experience required?

Yes. You should have completed Splunk Enterprise Administration (SP-ADM-FT or SESA + SEDA) before attending this course.

What certification does this course prepare me for?

This course prepares you for the Splunk Enterprise Security Certified Admin certification exam.

Is this course available as live remote online training?

Yes. IT Dojo offers this course as live remote online instruction. On-site delivery is also available.

How do I register?

IT Dojo training is employer sponsored. Contact IT Dojo via the Request Training form or call 757-216-3656.

Get More Information

We work with Government Agencies, Military, government contractors, and corporate clients. As much as we would love to, our business model does not include working with the general public.