<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26216" language="de" source="https://portal.flane.ch/swisscom/xml-course/splunk-asoar" lastchanged="2026-02-27T10:05:03+01:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Administering Splunk SOAR</title><productcode>ASOAR</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-ASOAR</fullproductcode><version>7.0</version><essentials>&lt;p&gt;To be successful, students must have a working understanding of these courses:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/splunk-iiss&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Investigating Incidents with Splunk SOAR &lt;span class=&quot;fl-prod-pcode&quot;&gt;(IISS)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;SOAR Administrators&lt;/p&gt;</audience><outline>&lt;h4&gt;Topic 1 &amp;ndash;Initial Configuration&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Describe SOAR operating concepts&lt;/li&gt;&lt;li&gt;Identify documentation and community resources&lt;/li&gt;&lt;li&gt;SOAR &amp;amp; Splunk Architecture&lt;/li&gt;&lt;li&gt;Product settings&lt;/li&gt;&lt;li&gt;Access control&lt;/li&gt;&lt;li&gt;Authentication settings&lt;/li&gt;&lt;li&gt;Response settings&lt;/li&gt;&lt;li&gt;Understanding roles&lt;/li&gt;&lt;li&gt;Creating users&lt;/li&gt;&lt;li&gt;Managing user access&lt;/li&gt;&lt;li&gt;Describe SOAR Automation Broker&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Topic 2 &amp;ndash; Apps, Assets and Playbooks&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Add and configure apps and assets&lt;/li&gt;&lt;li&gt;Manage playbooks&lt;/li&gt;&lt;li&gt;Ingesting Data&lt;/li&gt;&lt;li&gt;Labels and tags&lt;/li&gt;&lt;li&gt;Event settings&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Topic 3 &amp;ndash; Customization and Monitoring&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Create custom severity levels&lt;/li&gt;&lt;li&gt;Create custom status levels&lt;/li&gt;&lt;li&gt;Add custom fields and CEF settings&lt;/li&gt;&lt;li&gt;Create custom workbooks&lt;/li&gt;&lt;li&gt;Run reports&lt;/li&gt;&lt;li&gt;Use SOAR audit tools&lt;/li&gt;&lt;li&gt;Monitor system health&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Appendix: SOAR Automation Broker&lt;/h4&gt;</outline><essentials_plain>To be successful, students must have a working understanding of these courses:



- Investigating Incidents with Splunk SOAR (IISS)</essentials_plain><audience_plain>SOAR Administrators</audience_plain><outline_plain>Topic 1 –Initial Configuration


- Describe SOAR operating concepts
- Identify documentation and community resources
- SOAR &amp; Splunk Architecture
- Product settings
- Access control
- Authentication settings
- Response settings
- Understanding roles
- Creating users
- Managing user access
- Describe SOAR Automation Broker
Topic 2 – Apps, Assets and Playbooks


- Add and configure apps and assets
- Manage playbooks
- Ingesting Data
- Labels and tags
- Event settings
Topic 3 – Customization and Monitoring


- Create custom severity levels
- Create custom status levels
- Add custom fields and CEF settings
- Create custom workbooks
- Run reports
- Use SOAR audit tools
- Monitor system health

Appendix: SOAR Automation Broker</outline_plain><duration unit="d" days="0">3 Stunden</duration><pricelist><price country="SI" currency="EUR">1000.00</price><price country="US" currency="USD">500.00</price><price country="GR" currency="EUR">1000.00</price><price country="MK" currency="EUR">1000.00</price><price country="HU" currency="EUR">1000.00</price><price country="PL" currency="USD">500.00</price><price country="GB" currency="GBP">420.00</price><price country="DE" currency="EUR">500.00</price><price country="CA" currency="CAD">690.00</price><price country="CH" currency="CHF">550.00</price><price country="NL" currency="EUR">500.00</price></pricelist><miles><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue></miles></course>