Overview
This 13.5 hour Administering Splunk Enterprise Security training course prepares architects and systems administrators to install and configure Splunk Enterprise Security (ES). It covers ES event processing and normalization, deployment requirements, technology add-ons, dashboard dependencies, data models, managing risk, and customizing threat intelligence.
Skills Covered
Please refer to course overview.
Who Should Attend
Everyone can attend.
Course Curriculum
Prerequisites
To be successful, students should have a solid understanding of the following courses:
- Splunk Fundamentals 1
- Splunk Fundamentals 2
OR the following single-subject courses:
- What Is Splunk?
- Intro to Splunk
- Using Fields
- Scheduling Reports and Alerts
- Visualizations
- Leveraging Lookups and Subsearches
- Search Under the Hood
- Introduction to Knowledge Objects
- Creating Knowledge Objects
- Creating Field Extractions
- Enriching Data with Lookups
- Data Models
- Introduction to Dashboards
- Dynamic Dashboards
Students should also have completed the following courses:
- Splunk System Administration
- Splunk Data Administration
Course Modules
Exam & Certification
This course is not associated with any Certification.