LANTEC Logo
SP-USES - Using Splunk Enterprise Security

SP-USES - Using Splunk Enterprise Security

$1,500
2 days
Audience
Prerequisites

Course Description:

This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.

Course Objectives:

Upon completion of this course, students will:

  • Explain the role of a SIEM and the core capabilities of Splunk Enterprise Security.
  • Navigate the Analyst Queue and triage findings and finding groups.
  • Create and manage investigations using response plans, events, playbooks, and actions.
  • Use risk-based alerting, assets and identities, and adaptive responses.
  • Analyze security domain and intelligence dashboards.
  • Work with threat intelligence and protocol intelligence to investigate network activity.

Scheduled Courses

Oct 19, 2026
{
  "Params": {
    "source": "Event",
    "layout": "List for Course Detail Page",
    "filterby": "Course",
    "filtervalue": "28682",
    "sortby": "EventDateStart",
    "sortorder": "ASC",
    "limit": "9999",
    "enablepagination": "false",
    "emptymessage": "

This course isn't currently on the schedule, but we can add it. Just let us know.

", "object": "collection", "type": "module" }, "Pagination": { "CurrentPage": 0, "ItemsPerPage": 0, "NumberOfPages": 0, "TotalItemsCount": 0 }, "Parent": { "Id": 28682, "Name": "SP-USES - Using Splunk Enterprise Security", "Url": "/course/sp-uses-using-splunk-enterprise-security", "Url_List": [ "/course/sp-uses-using-splunk-enterprise-security" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security", "ParentId": 5934, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Course", "Module_ID": 5934, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2099-12-31T00:00:00", "SiteSearchKeywords": [], "Description": "

Course Description:

This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.

Course Objectives:

Upon completion of this course, students will:

  • Explain the role of a SIEM and the core capabilities of Splunk Enterprise Security.
  • Navigate the Analyst Queue and triage findings and finding groups.
  • Create and manage investigations using response plans, events, playbooks, and actions.
  • Use risk-based alerting, assets and identities, and adaptive responses.
  • Analyze security domain and intelligence dashboards.
  • Work with threat intelligence and protocol intelligence to investigate network activity.
", "Weighting": 0, "DisableForSiteSearch": false, "CreatedByMemberId": "0", "ItemCategories": [ "Courses", "Courses/Courses-Technical", "Courses/Courses-Technical/Cisco" ], "ItemCategoryIdList": [ 8587, 8590, 8592 ], "ItemTags": [ "Cisco", "Splunk" ], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "CourseTitle": "SP-USES - Using Splunk Enterprise Security", "CourseFiles": "/SP-USES - Using Splunk Enterprise Security Course Outline.pdf", "CourseFilesTitle": "Outline", "Intro": "This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.", "Days": "2", "Prerequisites": "Students should have a working understanding of Intro to Splunk, Using Fields, Visualizations, Search Under the Hood, Intro to Knowledge Objects, and Introduction to Dashboards.", "Audience": "Security operations center (SOC) analysts and security professionals who use Splunk Enterprise Security to identify, investigate, and respond to threats.", "Cost": "$1,500", "GoogleAnalyticsCode": "", "Popular": false, "Photo": "", "Disclaimer": "", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": { "type": "snippet", "alias": "_template_header", "name": "_Template - Header", "content": "
\r\n
\r\n
\r\n
\r\n
\r\n
{% component type: \"menu\", alias: \"social_menu\", layoutGroup: \"Default\" %}
\r\n
\r\n
\r\n
\r\n {% component type: \"menu\", alias: \"utility_menu\", layoutGroup: \"Default\" %} \r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n \"LANTEC\r\n
\r\n
\r\n
\r\n
\r\n {% component type:\"menu\", alias: \"main_menu\", layoutGroup: \"Default\" %}\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\"LANTEC
\r\n \r\n
\r\n
\r\n \r\n {% assign brcr = \"BACK\" %}\r\n \r\n\t
\r\n\t BACK\r\n\t
\r\n
", "enabled": true } }, "Items": [ { "Id": 28685, "Name": "SP-USES - Using Splunk Enterprise Security - VILT - 101926", "Url": "/event/sp-uses-using-splunk-enterprise-security-vilt-101926", "Url_List": [ "/event/sp-uses-using-splunk-enterprise-security-vilt-101926" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security-vilt-101926", "ParentId": 1827, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Event", "Module_ID": 1827, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2026-10-19T11:54:00", "SiteSearchKeywords": [], "Description": "", "Weighting": 0, "DisableForSiteSearch": false, "SKUCode": "81a79651-5357-4b6c-af5b-09924181d409", "Price": 1530.0000, "PriceHtml": "1,530.00", "priceWithTax": 1530.00, "priceWithTaxHtml": "1,530.00", "RecommendedPrice": 1500.0000, "RecommendedPriceHtml": "1,500.00", "RecommendedPriceWithTax": 1500.00, "RecommendedPriceWithTaxHtml": "1,500.00", "HideWhenFull": false, "AllowMultipleSubscriptionPerEmail": false, "Capacity": 0, "Allocation": 0, "EventDateStart": "2026-10-19T09:00:00", "EventDateEnd": "2026-10-20T17:00:00", "taxRate": 0.0, "VolumeDiscount": [ { "Price": 1530.0000, "Quantity": 0 } ], "CreatedByMemberId": "0", "ItemCategories": [], "ItemCategoryIdList": [], "ItemTags": [], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "Course": 28682, "Course_Name": "SP-USES - Using Splunk Enterprise Security", "Course_Url": "/course/sp-uses-using-splunk-enterprise-security", "Location": "vILT", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": {} }, { "Id": 28686, "Name": "SP-USES - Using Splunk Enterprise Security - VILT - 121426", "Url": "/event/sp-uses-using-splunk-enterprise-security-vilt-121426", "Url_List": [ "/event/sp-uses-using-splunk-enterprise-security-vilt-121426" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security-vilt-121426", "ParentId": 1827, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Event", "Module_ID": 1827, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2026-12-14T11:54:00", "SiteSearchKeywords": [], "Description": "", "Weighting": 0, "DisableForSiteSearch": false, "SKUCode": "8b9d72c8-3267-4a5c-9227-87fe7f1d5e24", "Price": 1530.0000, "PriceHtml": "1,530.00", "priceWithTax": 1530.00, "priceWithTaxHtml": "1,530.00", "RecommendedPrice": 1500.0000, "RecommendedPriceHtml": "1,500.00", "RecommendedPriceWithTax": 1500.00, "RecommendedPriceWithTaxHtml": "1,500.00", "HideWhenFull": false, "AllowMultipleSubscriptionPerEmail": false, "Capacity": 0, "Allocation": 0, "EventDateStart": "2026-12-14T09:00:00", "EventDateEnd": "2026-12-15T17:00:00", "taxRate": 0.0, "VolumeDiscount": [ { "Price": 1530.0000, "Quantity": 0 } ], "CreatedByMemberId": "0", "ItemCategories": [], "ItemCategoryIdList": [], "ItemTags": [], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "Course": 28682, "Course_Name": "SP-USES - Using Splunk Enterprise Security", "Course_Url": "/course/sp-uses-using-splunk-enterprise-security", "Location": "vILT", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": {} } ] }
Dec 14, 2026
{
  "Params": {
    "source": "Event",
    "layout": "List for Course Detail Page",
    "filterby": "Course",
    "filtervalue": "28682",
    "sortby": "EventDateStart",
    "sortorder": "ASC",
    "limit": "9999",
    "enablepagination": "false",
    "emptymessage": "

This course isn't currently on the schedule, but we can add it. Just let us know.

", "object": "collection", "type": "module" }, "Pagination": { "CurrentPage": 0, "ItemsPerPage": 0, "NumberOfPages": 0, "TotalItemsCount": 0 }, "Parent": { "Id": 28682, "Name": "SP-USES - Using Splunk Enterprise Security", "Url": "/course/sp-uses-using-splunk-enterprise-security", "Url_List": [ "/course/sp-uses-using-splunk-enterprise-security" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security", "ParentId": 5934, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Course", "Module_ID": 5934, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2099-12-31T00:00:00", "SiteSearchKeywords": [], "Description": "

Course Description:

This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.

Course Objectives:

Upon completion of this course, students will:

  • Explain the role of a SIEM and the core capabilities of Splunk Enterprise Security.
  • Navigate the Analyst Queue and triage findings and finding groups.
  • Create and manage investigations using response plans, events, playbooks, and actions.
  • Use risk-based alerting, assets and identities, and adaptive responses.
  • Analyze security domain and intelligence dashboards.
  • Work with threat intelligence and protocol intelligence to investigate network activity.
", "Weighting": 0, "DisableForSiteSearch": false, "CreatedByMemberId": "0", "ItemCategories": [ "Courses", "Courses/Courses-Technical", "Courses/Courses-Technical/Cisco" ], "ItemCategoryIdList": [ 8587, 8590, 8592 ], "ItemTags": [ "Cisco", "Splunk" ], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "CourseTitle": "SP-USES - Using Splunk Enterprise Security", "CourseFiles": "/SP-USES - Using Splunk Enterprise Security Course Outline.pdf", "CourseFilesTitle": "Outline", "Intro": "This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.", "Days": "2", "Prerequisites": "Students should have a working understanding of Intro to Splunk, Using Fields, Visualizations, Search Under the Hood, Intro to Knowledge Objects, and Introduction to Dashboards.", "Audience": "Security operations center (SOC) analysts and security professionals who use Splunk Enterprise Security to identify, investigate, and respond to threats.", "Cost": "$1,500", "GoogleAnalyticsCode": "", "Popular": false, "Photo": "", "Disclaimer": "", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": { "type": "snippet", "alias": "_template_header", "name": "_Template - Header", "content": "
\r\n
\r\n
\r\n
\r\n
\r\n
{% component type: \"menu\", alias: \"social_menu\", layoutGroup: \"Default\" %}
\r\n
\r\n
\r\n
\r\n {% component type: \"menu\", alias: \"utility_menu\", layoutGroup: \"Default\" %} \r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n \"LANTEC\r\n
\r\n
\r\n
\r\n
\r\n {% component type:\"menu\", alias: \"main_menu\", layoutGroup: \"Default\" %}\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\r\n
\"LANTEC
\r\n \r\n
\r\n
\r\n \r\n {% assign brcr = \"BACK\" %}\r\n \r\n\t
\r\n\t BACK\r\n\t
\r\n
", "enabled": true } }, "Items": [ { "Id": 28685, "Name": "SP-USES - Using Splunk Enterprise Security - VILT - 101926", "Url": "/event/sp-uses-using-splunk-enterprise-security-vilt-101926", "Url_List": [ "/event/sp-uses-using-splunk-enterprise-security-vilt-101926" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security-vilt-101926", "ParentId": 1827, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Event", "Module_ID": 1827, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2026-10-19T11:54:00", "SiteSearchKeywords": [], "Description": "", "Weighting": 0, "DisableForSiteSearch": false, "SKUCode": "81a79651-5357-4b6c-af5b-09924181d409", "Price": 1530.0000, "PriceHtml": "1,530.00", "priceWithTax": 1530.00, "priceWithTaxHtml": "1,530.00", "RecommendedPrice": 1500.0000, "RecommendedPriceHtml": "1,500.00", "RecommendedPriceWithTax": 1500.00, "RecommendedPriceWithTaxHtml": "1,500.00", "HideWhenFull": false, "AllowMultipleSubscriptionPerEmail": false, "Capacity": 0, "Allocation": 0, "EventDateStart": "2026-10-19T09:00:00", "EventDateEnd": "2026-10-20T17:00:00", "taxRate": 0.0, "VolumeDiscount": [ { "Price": 1530.0000, "Quantity": 0 } ], "CreatedByMemberId": "0", "ItemCategories": [], "ItemCategoryIdList": [], "ItemTags": [], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "Course": 28682, "Course_Name": "SP-USES - Using Splunk Enterprise Security", "Course_Url": "/course/sp-uses-using-splunk-enterprise-security", "Location": "vILT", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": {} }, { "Id": 28686, "Name": "SP-USES - Using Splunk Enterprise Security - VILT - 121426", "Url": "/event/sp-uses-using-splunk-enterprise-security-vilt-121426", "Url_List": [ "/event/sp-uses-using-splunk-enterprise-security-vilt-121426" ], "UrlSlug": "sp-uses-using-splunk-enterprise-security-vilt-121426", "ParentId": 1827, "ParentId_List": [ -1 ], "ParentName": "", "ParentUrl": "", "TemplateName": "", "Module_Alias": "Event", "Module_ID": 1827, "Enabled": true, "ReleaseDate": "2026-08-25T00:00:00", "ExpiryDate": "2026-12-14T11:54:00", "SiteSearchKeywords": [], "Description": "", "Weighting": 0, "DisableForSiteSearch": false, "SKUCode": "8b9d72c8-3267-4a5c-9227-87fe7f1d5e24", "Price": 1530.0000, "PriceHtml": "1,530.00", "priceWithTax": 1530.00, "priceWithTaxHtml": "1,530.00", "RecommendedPrice": 1500.0000, "RecommendedPriceHtml": "1,500.00", "RecommendedPriceWithTax": 1500.00, "RecommendedPriceWithTaxHtml": "1,500.00", "HideWhenFull": false, "AllowMultipleSubscriptionPerEmail": false, "Capacity": 0, "Allocation": 0, "EventDateStart": "2026-12-14T09:00:00", "EventDateEnd": "2026-12-15T17:00:00", "taxRate": 0.0, "VolumeDiscount": [ { "Price": 1530.0000, "Quantity": 0 } ], "CreatedByMemberId": "0", "ItemCategories": [], "ItemCategoryIdList": [], "ItemTags": [], "Author": 0, "Author_Name": "", "Author_Url": "", "Item_Rating": 0, "DnDOrder": 0, "Course": 28682, "Course_Name": "SP-USES - Using Splunk Enterprise Security", "Course_Url": "/course/sp-uses-using-splunk-enterprise-security", "Location": "vILT", "ShowPageForSearchEngine": true, "MetaTitle": "", "SEOTitle": "", "MetaDescription": "", "CanonicalLink": "", "SocialMetaTags": "", "SeoPriority": 0.5, "EnableAMP": false, "AMPContent": "", "OpenGraphProperties": { "title": null, "type": null, "url": null, "locale": null, "image": null }, "ExternalId": 0, "Params": {} } ] }

Need to Request This Course On a Different Day?

LANTEC is very responsive to local client needs and unique or custom class demands. If you require a delivery date option for a class title on our schedule, please submit your specific request for immediate consideration. We can often accommodate countless additional courses NOT available on our public schedules, please inquire for personal assistance.
Want to schedule it?