Security operations center (SOC) analysts and security professionals who use Splunk Enterprise Security to identify, investigate, and respond to threats.
Prerequisites:
Students should have a working understanding of Intro to Splunk, Using Fields, Visualizations, Search Under the Hood, Intro to Knowledge Objects, and Introduction to Dashboards.
Course Description:
This two-day instructor-led course prepares SOC analysts to use Splunk Enterprise Security (ES). Students learn to identify and track incidents, analyze security risks, use risk-based alerting and threat intelligence, investigate suspicious activity, and work with the dashboards and response tools used in day-to-day security operations.
Course Objectives:
Upon completion of this course, students will:
Explain the role of a SIEM and the core capabilities of Splunk Enterprise Security.
Navigate the Analyst Queue and triage findings and finding groups.
Create and manage investigations using response plans, events, playbooks, and actions.
Use risk-based alerting, assets and identities, and adaptive responses.
Analyze security domain and intelligence dashboards.
Work with threat intelligence and protocol intelligence to investigate network activity.
Scheduled Courses
Oct 19, 2026
vILT (Virtual)
Dec 14, 2026
vILT (Virtual)
Want to Take this Course on a Different Day?
LANTEC is very responsive to local client needs and unique or custom class demands. If you require a delivery date option for a class title on our schedule, please constact us. We can often accommodate countless additional courses NOT available on our public schedules, please inquire for personal assistance.