<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26214" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/splunk-uses" lastchanged="2026-02-19T15:52:57+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Using Splunk Enterprise Security</title><productcode>USES</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-USES</fullproductcode><version>8</version><essentials>&lt;p&gt;To be successful, students should have a working understanding of the topics covered in the following Splunk courses:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk (eLearning)&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Visualizations&lt;/li&gt;&lt;li&gt;Search Under the Hood&lt;/li&gt;&lt;li&gt;Intro to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/splunk-itd&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Introduction to Dashboards &lt;span class=&quot;fl-prod-pcode&quot;&gt;(ITD)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;SOC Analysts.&lt;/p&gt;</audience><contents>&lt;h5&gt;Module 1 - ES Fundamentals&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain the function of a SIEM&lt;/li&gt;&lt;li&gt;Give an overview of Splunk Enterprise Security (ES)&lt;/li&gt;&lt;li&gt;Understand how ES uses data models&lt;/li&gt;&lt;li&gt;Describe detections and findings&lt;/li&gt;&lt;li&gt;Identify ES roles and permissions&lt;/li&gt;&lt;li&gt;Give an overview of ES navigation&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2 - Exploring the Analyst Queue&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explore the Analyst Queue&lt;/li&gt;&lt;li&gt;Filtering&lt;/li&gt;&lt;li&gt;Triage Findings and Finding Groups&lt;/li&gt;&lt;li&gt;Create ad hoc Findings&lt;/li&gt;&lt;li&gt;Suppress Findings from the Analyst Queue&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3 - Working with Investigations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of an investigation&lt;/li&gt;&lt;li&gt;Demonstrate how to create an investigation&lt;/li&gt;&lt;li&gt;Use Response Plans&lt;/li&gt;&lt;li&gt;Add Splunk events to an investigation&lt;/li&gt;&lt;li&gt;Use Playbooks and Actions&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4 - Risk-based Alerting&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of risk and Risk-Based Alerting (RBA)&lt;/li&gt;&lt;li&gt;Explain risk scores and how to change an entity&amp;#039;s risk score&lt;/li&gt;&lt;li&gt;Review the Risk Analysis dashboard&lt;/li&gt;&lt;li&gt;Describe annotations&lt;/li&gt;&lt;li&gt;View risk information in Analyst Queue findings&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5 - Assets &amp;amp; Identities&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of the ES Assets and Identities (A&amp;amp;I) framework&lt;/li&gt;&lt;li&gt;Show where asset or identity data is missing from ES findings or dashboards&lt;/li&gt;&lt;li&gt;View the A&amp;amp;I Management Interface&lt;/li&gt;&lt;li&gt;View the contents of an asset or identity lookup table&lt;/li&gt;&lt;li&gt;Identify A&amp;amp;I field matching criteria&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6 - Adaptive Responses&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe Adaptive Responses&lt;/li&gt;&lt;li&gt;Identify the default ES Adaptive Responses&lt;/li&gt;&lt;li&gt;Discuss Adaptive Response invocation methods&lt;/li&gt;&lt;li&gt;Troubleshoot Adaptive Response issues&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7 - Security Domain Dashboards&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Use ES to inspect events containing information relevant to active or past incident investigation&lt;/li&gt;&lt;li&gt;Identify ES Security Domains&lt;/li&gt;&lt;li&gt;Use the Security Domain dashboards&lt;/li&gt;&lt;li&gt;Launch Security Domain dashboards from the Analyst Queue and from field action menus in search results&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 8 - Intelligence Dashboards&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Use the Web Intelligence dashboards to analyze your network environment&lt;/li&gt;&lt;li&gt;Filter and highlight events&lt;/li&gt;&lt;li&gt;Understand and use User Intelligence dashboards&lt;/li&gt;&lt;li&gt;Use Investigators to analyze events related to an asset or identity&lt;/li&gt;&lt;li&gt;Use Access Anomalies to detect suspicious access patterns&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9 - Threat Intelligence&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of the Threat Intelligence framework&lt;/li&gt;&lt;li&gt;Identify where Threat Intelligence is configured&lt;/li&gt;&lt;li&gt;Observe Threat Findings&lt;/li&gt;&lt;li&gt;View downloaded Threat Indicators&lt;/li&gt;&lt;li&gt;Troubleshooting Threat Intelligence&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 10 - Protocol Intelligence&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain how network data is input into Splunk events&lt;/li&gt;&lt;li&gt;Describe stream events&lt;/li&gt;&lt;li&gt;Give an overview of the Protocol Intelligence dashboards and how they can be used to analyze network data&lt;/li&gt;&lt;/ul&gt;</contents><essentials_plain>To be successful, students should have a working understanding of the topics covered in the following Splunk courses:


- Intro to Splunk (eLearning)
- Using Fields (SUF)
- Visualizations
- Search Under the Hood
- Intro to Knowledge Objects
- Introduction to Dashboards (ITD)</essentials_plain><audience_plain>SOC Analysts.</audience_plain><contents_plain>Module 1 - ES Fundamentals


- Explain the function of a SIEM
- Give an overview of Splunk Enterprise Security (ES)
- Understand how ES uses data models
- Describe detections and findings
- Identify ES roles and permissions
- Give an overview of ES navigation
Module 2 - Exploring the Analyst Queue


- Explore the Analyst Queue
- Filtering
- Triage Findings and Finding Groups
- Create ad hoc Findings
- Suppress Findings from the Analyst Queue
Module 3 - Working with Investigations


- Give an overview of an investigation
- Demonstrate how to create an investigation
- Use Response Plans
- Add Splunk events to an investigation
- Use Playbooks and Actions
Module 4 - Risk-based Alerting


- Give an overview of risk and Risk-Based Alerting (RBA)
- Explain risk scores and how to change an entity's risk score
- Review the Risk Analysis dashboard
- Describe annotations
- View risk information in Analyst Queue findings
Module 5 - Assets &amp; Identities


- Give an overview of the ES Assets and Identities (A&amp;I) framework
- Show where asset or identity data is missing from ES findings or dashboards
- View the A&amp;I Management Interface
- View the contents of an asset or identity lookup table
- Identify A&amp;I field matching criteria
Module 6 - Adaptive Responses


- Describe Adaptive Responses
- Identify the default ES Adaptive Responses
- Discuss Adaptive Response invocation methods
- Troubleshoot Adaptive Response issues
Module 7 - Security Domain Dashboards


- Use ES to inspect events containing information relevant to active or past incident investigation
- Identify ES Security Domains
- Use the Security Domain dashboards
- Launch Security Domain dashboards from the Analyst Queue and from field action menus in search results
Module 8 - Intelligence Dashboards


- Use the Web Intelligence dashboards to analyze your network environment
- Filter and highlight events
- Understand and use User Intelligence dashboards
- Use Investigators to analyze events related to an asset or identity
- Use Access Anomalies to detect suspicious access patterns
Module 9 - Threat Intelligence


- Give an overview of the Threat Intelligence framework
- Identify where Threat Intelligence is configured
- Observe Threat Findings
- View downloaded Threat Indicators
- Troubleshooting Threat Intelligence
Module 10 - Protocol Intelligence


- Explain how network data is input into Splunk events
- Describe stream events
- Give an overview of the Protocol Intelligence dashboards and how they can be used to analyze network data</contents_plain><duration unit="d" days="2">2 days</duration><pricelist><price country="US" currency="USD">1500.00</price><price country="GB" currency="GBP">1250.00</price><price country="SI" currency="EUR">1500.00</price><price country="PL" currency="USD">1500.00</price><price country="DE" currency="EUR">1500.00</price><price country="AT" currency="EUR">1500.00</price><price country="SE" currency="EUR">1500.00</price><price country="FR" currency="EUR">1500.00</price><price country="IT" currency="USD">1500.00</price><price country="CA" currency="CAD">2070.00</price><price country="CH" currency="CHF">1650.00</price><price country="NL" currency="EUR">1500.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue></miles></course>