<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="29836" language="de" source="https://portal.flane.ch/swisscom/xml-course/splunk-iiss" lastchanged="2026-03-18T17:25:23+01:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Investigating Incidents with Splunk SOAR</title><productcode>IISS</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-IISS</fullproductcode><version>7.0</version><essentials>&lt;p&gt;Basic Security operations knowledge.&lt;/p&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;SOC analysts&lt;/li&gt;&lt;li&gt;SOAR Administrators&lt;/li&gt;&lt;li&gt;Automation Engineers&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;h5&gt;Topic 1 &amp;ndash; Starting Investigations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;SOAR investigation concepts&lt;/li&gt;&lt;li&gt;ROI view&lt;/li&gt;&lt;li&gt;Using the Analyst Queue&lt;/li&gt;&lt;li&gt;Using indicators&lt;/li&gt;&lt;li&gt;Using search&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 2 &amp;ndash; Working on Events&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Use the Investigation page to work on events&lt;/li&gt;&lt;li&gt;Use the heads-up display&lt;/li&gt;&lt;li&gt;Set event status and other fields&lt;/li&gt;&lt;li&gt;Use notes and comments&lt;/li&gt;&lt;li&gt;How SLA affects event workflow&lt;/li&gt;&lt;li&gt;Using artifacts and files&lt;/li&gt;&lt;li&gt;Exporting events&lt;/li&gt;&lt;li&gt;Executing actions and playbooks&lt;/li&gt;&lt;li&gt;Managing approvals&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Topic 3 &amp;ndash; Cases: Complex Events&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Use case management for complex investigations&lt;/li&gt;&lt;li&gt;Use case workflows&lt;/li&gt;&lt;li&gt;Mark evidence&lt;/li&gt;&lt;li&gt;Running reports&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>Basic Security operations knowledge.</essentials_plain><audience_plain>- SOC analysts
- SOAR Administrators
- Automation Engineers</audience_plain><outline_plain>Topic 1 – Starting Investigations


- SOAR investigation concepts
- ROI view
- Using the Analyst Queue
- Using indicators
- Using search
Topic 2 – Working on Events


- Use the Investigation page to work on events
- Use the heads-up display
- Set event status and other fields
- Use notes and comments
- How SLA affects event workflow
- Using artifacts and files
- Exporting events
- Executing actions and playbooks
- Managing approvals
Topic 3 – Cases: Complex Events


- Use case management for complex investigations
- Use case workflows
- Mark evidence
- Running reports</outline_plain><duration unit="d" days="0">3 Stunden</duration><pricelist><price country="US" currency="USD">500.00</price><price country="GB" currency="GBP">420.00</price><price country="PL" currency="USD">500.00</price><price country="DE" currency="EUR">500.00</price><price country="NL" currency="EUR">500.00</price><price country="CA" currency="CAD">690.00</price><price country="CH" currency="CHF">500.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue></miles></course>