757-216-3656 | Monday–Friday 8:30 AM – 4:30 PM | info@itdojo.com

Course Duration

1 Day

Audience

Employees of federal, state and local governments; and businesses working with the government.

Prerequisites

Basic familiarity with Splunk SOAR and security operations concepts. Python programming knowledge is helpful for custom action development.

Course Description

This 9-hour introductory course prepares IT and security practitioners to plan, design, create, and debug basic Splunk SOAR playbooks. Students learn playbook design principles, use the visual playbook editor to build automation workflows, work with SOAR actions and connectors, and implement playbook best practices for security operations automation.

Learning Objectives

  • Understand automation best practices and playbook design principles
  • Use the Splunk SOAR visual playbook editor to build workflows
  • Configure SOAR actions and work with app connectors
  • Implement decision logic and parallel execution in playbooks
  • Debug and troubleshoot playbook execution issues
  • Apply playbook best practices for SOC automation

Course Outline

Introduction to Playbooks
  • Automation best practices
  • Designing playbooks
  • Python support in SOAR
  • Using the playbook manager
Visual Playbook Editor
  • Editor interface and workflow
  • Adding and connecting actions
  • Decision logic and branching
  • Parallel execution
Working with Actions
  • SOAR app connectors
  • Action inputs and outputs
  • Testing and debugging actions
  • Playbook testing and validation

Frequently Asked Questions

What does the Developing SOAR Playbooks course cover?

This 1-day course covers Splunk SOAR playbook fundamentals -- automation design, using the visual playbook editor, working with SOAR actions and connectors, and debugging playbooks.

Do I need Python experience?

Python knowledge is helpful for custom action development but not required to complete basic playbooks using the visual editor.

Is this course available as live remote online training?

Yes. IT Dojo offers this course as live remote online instruction. On-site delivery is also available.

How do I register?

IT Dojo training is employer sponsored. Contact IT Dojo via the Request Training form or call 757-216-3656.

Get More Information

We work with Government Agencies, Military, government contractors, and corporate clients. As much as we would love to, our business model does not include working with the general public.