Course Summary
The Administering Splunk Enterprise Security course focuses on Administrators who manage a Splunk Enterprise Security environment, including ES event processing and normalization, deployment requirements, technology add-ons, settings, risk analysis settings, threat intelligence and protocol intelligence configuration, and customizations.
You will gain skills like:
• Advanced configuration of Splunk Enterprise Security (ES)
• Security monitoring and incident response
• Customizing security dashboards and alerts
• Implementing security data models and correlation searches
• Managing and optimizing security-related data ingestion and indexing
Module 1: Identifying normal ES use cases
Module 2: Examining deployment requirements for typical ES installs
Module 3: Knowing how to install ES and gather information for lookups
Module 4: Knowing the steps to setting up inputs using technology add-ons
Module 5: Creating custom correlation searches
Module 6: Configuring ES risk analysis, threat, and protocol intelligence
Module 7: Fine tuning ES settings and other customizations
Other Popular Courses
Executive Cyber Risk Certification (ECRC)
- Duration: 2 Days
- Language: English
- Level: Intermediate
- Exam: ECRC
Mastering Communication & Presentation Te...
- Duration: 4 Days
- Language: Danish
- Level: Intermediate
- Exam: MCPT
Next Generation Mindfulness
- Duration: 1 Days
- Language: English
- Level: Foundation
- Exam: NGM