<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26213" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/splunk-ases" lastchanged="2026-02-27T14:07:19+01:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Administering Splunk Enterprise Security</title><productcode>ASES</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-ASES</fullproductcode><version>8.1</version><essentials>&lt;p&gt;To be successful, students must have completed the following Splunk Education course:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-uses&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Splunk Enterprise Security &lt;span class=&quot;fl-prod-pcode&quot;&gt;(USES)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Students should also be familiar with the topics covered in the following courses:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to Splunk&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-suf&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Using Fields &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SUF)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Visualizations&lt;/li&gt;&lt;li&gt;Search Under the Hood&lt;/li&gt;&lt;li&gt;Intro to Knowledge Objects&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-cko&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Knowledge Objects &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CKO)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-cfe&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Creating Field Extractions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CFE)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-edl&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Enriching Data with Lookups &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDL)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-sdm&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Data Models &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SDM)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-itd&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Introduction to Dashboards &lt;span class=&quot;fl-prod-pcode&quot;&gt;(ITD)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-sesa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise System Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SESA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; AND &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-seda&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Enterprise Data Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEDA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; OR &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/fr/course/splunk-sca&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Splunk Cloud Administration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SCA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;SOC Analyst&lt;/li&gt;&lt;li&gt;SOC Engineer&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;h5&gt;Module 1 - Introduction to Enterprise Security&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain the function of a SIEM&lt;/li&gt;&lt;li&gt;Give an overview of Splunk&amp;rsquo;s Enterprise Security (ES)&lt;/li&gt;&lt;li&gt;Describe detections and findings&lt;/li&gt;&lt;li&gt;Configure ES roles and permissions&lt;/li&gt;&lt;li&gt;Give an overview of ES navigation&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2 - Customizing the Analyst Queue and findings&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of the Analyst Queue&lt;/li&gt;&lt;li&gt;Create and use Analyst Queue Views&lt;/li&gt;&lt;li&gt;Customize the Analyst Queue&lt;/li&gt;&lt;li&gt;Modify Urgency&lt;/li&gt;&lt;li&gt;Create new Status values&lt;/li&gt;&lt;li&gt;Add fields to Finding attributes&lt;/li&gt;&lt;li&gt;Create ad hoc Findings&lt;/li&gt;&lt;li&gt;Suppress Findings&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3 - Working with Investigations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of an investigation&lt;/li&gt;&lt;li&gt;Use and create Response Plans&lt;/li&gt;&lt;li&gt;Add Splunk events to an investigation&lt;/li&gt;&lt;li&gt;Use Playbooks and Actions&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4 - Asset &amp;amp; Identity Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Review the Asset and Identity Management interface&lt;/li&gt;&lt;li&gt;Describe Asset and Identity KV Store collections&lt;/li&gt;&lt;li&gt;Configure and add asset and identity lookups to the interface&lt;/li&gt;&lt;li&gt;Configure settings and fields for asset and identity lookups&lt;/li&gt;&lt;li&gt;Explain the asset and identity merge process&lt;/li&gt;&lt;li&gt;Describe the process for retrieving LDAP data for an asset or identity lookup&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5 - Data Normalization&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Understand how ES uses accelerated data models&lt;/li&gt;&lt;li&gt;Verify data is correctly configured for use in ES&lt;/li&gt;&lt;li&gt;Validate normalization configurations&lt;/li&gt;&lt;li&gt;Install additional add-ons&lt;/li&gt;&lt;li&gt;Ingest custom data in ES&lt;/li&gt;&lt;li&gt;Create an add-on for a custom sourcetype&lt;/li&gt;&lt;li&gt;Describe add-on troubleshooting&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6 - Detection Engineering&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of how to create Event-based detections&lt;/li&gt;&lt;li&gt;Review the Detection Editor&lt;/li&gt;&lt;li&gt;Give an overview of how to create Finding-based detections&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7 - Risk-Based Alerting&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of Risk-Based Alerting (RBA)&lt;/li&gt;&lt;li&gt;Explain risk scores and how they can be changed by detections or manually&lt;/li&gt;&lt;li&gt;Review the Risk analysis dashboard&lt;/li&gt;&lt;li&gt;Understand Finding-based detections&lt;/li&gt;&lt;li&gt;Describe annotations&lt;/li&gt;&lt;li&gt;View risk information in Analyst Queue findings&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 8 - Managing Threat Intelligence&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Understand and configure threat intelligence&lt;/li&gt;&lt;li&gt;Use the Threat Intelligence interface to configure threat lists&lt;/li&gt;&lt;li&gt;Configure new threat lists&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9 - Post-Deployment Configuration&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Give an overview of general ES install requirements&lt;/li&gt;&lt;li&gt;Explain the different add-ons and where they are installed&lt;/li&gt;&lt;li&gt;Provide ES pre-installation requirements&lt;/li&gt;&lt;li&gt;Describe the Splunk_TA_ForIndexers app and where it is installed&lt;/li&gt;&lt;li&gt;Set general configuration options&lt;/li&gt;&lt;li&gt;Configure local and cloud domain information&lt;/li&gt;&lt;li&gt;Work with the Incident Review KV Store&lt;/li&gt;&lt;li&gt;Customize navigation&lt;/li&gt;&lt;li&gt;Configure Key Indicator searches&lt;/li&gt;&lt;/ul&gt;</contents><essentials_plain>To be successful, students must have completed the following Splunk Education course:



- Using Splunk Enterprise Security (USES)
Students should also be familiar with the topics covered in the following courses:



- Intro to Splunk
- Using Fields (SUF)
- Visualizations
- Search Under the Hood
- Intro to Knowledge Objects
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Enriching Data with Lookups (EDL)
- Data Models (SDM)
- Introduction to Dashboards (ITD)
- Splunk Enterprise System Administration (SESA) AND Splunk Enterprise Data Administration (SEDA) OR Splunk Cloud Administration (SCA)</essentials_plain><audience_plain>- SOC Analyst
- SOC Engineer</audience_plain><contents_plain>Module 1 - Introduction to Enterprise Security


- Explain the function of a SIEM
- Give an overview of Splunk’s Enterprise Security (ES)
- Describe detections and findings
- Configure ES roles and permissions
- Give an overview of ES navigation
Module 2 - Customizing the Analyst Queue and findings


- Give an overview of the Analyst Queue
- Create and use Analyst Queue Views
- Customize the Analyst Queue
- Modify Urgency
- Create new Status values
- Add fields to Finding attributes
- Create ad hoc Findings
- Suppress Findings
Module 3 - Working with Investigations


- Give an overview of an investigation
- Use and create Response Plans
- Add Splunk events to an investigation
- Use Playbooks and Actions
Module 4 - Asset &amp; Identity Management


- Review the Asset and Identity Management interface
- Describe Asset and Identity KV Store collections
- Configure and add asset and identity lookups to the interface
- Configure settings and fields for asset and identity lookups
- Explain the asset and identity merge process
- Describe the process for retrieving LDAP data for an asset or identity lookup
Module 5 - Data Normalization


- Understand how ES uses accelerated data models
- Verify data is correctly configured for use in ES
- Validate normalization configurations
- Install additional add-ons
- Ingest custom data in ES
- Create an add-on for a custom sourcetype
- Describe add-on troubleshooting
Module 6 - Detection Engineering


- Give an overview of how to create Event-based detections
- Review the Detection Editor
- Give an overview of how to create Finding-based detections
Module 7 - Risk-Based Alerting


- Give an overview of Risk-Based Alerting (RBA)
- Explain risk scores and how they can be changed by detections or manually
- Review the Risk analysis dashboard
- Understand Finding-based detections
- Describe annotations
- View risk information in Analyst Queue findings
Module 8 - Managing Threat Intelligence


- Understand and configure threat intelligence
- Use the Threat Intelligence interface to configure threat lists
- Configure new threat lists
Module 9 - Post-Deployment Configuration


- Give an overview of general ES install requirements
- Explain the different add-ons and where they are installed
- Provide ES pre-installation requirements
- Describe the Splunk_TA_ForIndexers app and where it is installed
- Set general configuration options
- Configure local and cloud domain information
- Work with the Incident Review KV Store
- Customize navigation
- Configure Key Indicator searches</contents_plain><duration unit="d" days="2">2 jours</duration><pricelist><price country="US" currency="USD">1500.00</price><price country="GB" currency="GBP">1250.00</price><price country="PL" currency="USD">1500.00</price><price country="SI" currency="EUR">1500.00</price><price country="DE" currency="EUR">1500.00</price><price country="AT" currency="EUR">1500.00</price><price country="SE" currency="EUR">1500.00</price><price country="IT" currency="USD">1500.00</price><price country="CA" currency="CAD">2070.00</price><price country="CH" currency="CHF">1650.00</price><price country="NL" currency="EUR">1500.00</price><price country="FR" currency="EUR">1500.00</price></pricelist><miles><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue><milesvalue country="NL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">150.00</milesvalue></miles></course>