"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to SIEM
- SIEM fundamentals
- Security monitoring
- Log management
- Event correlation
- Threat detection
- SIEM use cases
Module 2: Introduction to Splunk
- Splunk platform overview
- Splunk architecture
- Core components
- Search interface
- Splunk terminology
- Security use cases
Module 3: Splunk Architecture
- Search heads
- Indexers
- Forwarders
- Deployment components
- Data flow
- Distributed architecture
Module 4: Data Collection & Ingestion
- Data sources
- Log collection
- Forwarders
- Data inputs
- Source types
- Data onboarding
Module 5: Indexes & Data Management
- Splunk indexes
- Index configuration
- Data organization
- Retention concepts
- Data lifecycle
- Index management
Module 6: Search Processing Language Fundamentals
- SPL fundamentals
- Search commands
- Filtering
- Fields
- Operators
- Search pipelines
Module 7: Advanced SPL
- Statistical commands
- Aggregation
- Data transformation
- Subsearches
- Lookup tables
- Search optimization
Module 8: Fields & Data Extraction
- Field discovery
- Field extraction
- Regular expressions
- Calculated fields
- Field aliases
- Data normalization
Module 9: Reports & Dashboards
- Report creation
- Dashboard development
- Visualizations
- Security metrics
- Dashboard panels
- Interactive reporting
Module 10: Alerts & Notifications
- Alert creation
- Alert conditions
- Scheduled searches
- Real-time alerts
- Alert actions
- Alert management
Module 11: Security Monitoring with Splunk
- Security events
- Authentication monitoring
- Network monitoring
- Endpoint monitoring
- Application monitoring
- Suspicious activity
Module 12: Splunk Enterprise Security
- Enterprise Security overview
- Security domains
- Notable events
- Risk-based alerting
- Security investigations
- Analyst workflows
Module 13: Threat Detection
- Detection fundamentals
- Detection use cases
- Behavioral indicators
- Anomaly detection
- Correlation searches
- Detection validation
Module 14: Log Analysis & Investigation
- Windows logs
- Linux logs
- Firewall logs
- Authentication logs
- Application logs
- Investigation techniques
Module 15: Threat Intelligence
- Threat intelligence fundamentals
- Indicators of compromise
- Intelligence enrichment
- Threat feeds
- Indicator matching
- Investigation context
Module 16: MITRE ATT&CK Integration
- MITRE ATT&CK fundamentals
- Tactics and techniques
- Detection mapping
- Threat behaviors
- Security use cases
- Coverage analysis
Module 17: Incident Investigation
- Alert triage
- Event investigation
- Timeline development
- Evidence correlation
- Root cause analysis
- Investigation documentation
Module 18: Incident Response Workflows
- Incident classification
- Prioritization
- Escalation
- Containment support
- Response coordination
- Post-incident review
Module 19: Splunk Use Case Development
- Security use cases
- Detection requirements
- Data requirements
- Search development
- Testing and tuning
- Use case lifecycle
Module 20: SIEM Optimization
- Search performance
- Alert tuning
- False-positive reduction
- Data quality
- Detection effectiveness
- Operational efficiency
Module 21: SOC Operations with Splunk
- SOC workflows
- Analyst dashboards
- Alert management
- Case investigation
- Security reporting
- Operational metrics
Module 22: Practical Splunk Security Project
- Security data onboarding
- SPL development
- Dashboard creation
- Detection development
- Incident investigation
- Security reporting
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device