Advanced SOAR Implementation

Course code: SPLUNKAPI

This 13.5 hour(3 Days) course is intended for experienced SOAR consultants who will be responsible for complex SOAR solution development, and will prepare the attendee to integrate SOAR with Splunk as well as develop playbooks requiring custom coding and REST API usage.
Potential attendees have received a passing grade in all prerequisite courses, and must ensure they can devote all of their attention to the class, as the course work is very challenging. Students will develop a custom solution with SOAR, Splunk and custom Python code. The labs provide requirements for the solution; the student must plan and execute the development. This will require thoughtful focus, experimentation and problem-solving skills.

1 600 EUR

1 936 EUR including VAT

The earliest date from 08.01.2025

Selection of dates
onas
Do you have a question?
+420 731 175 867 edu@edutrainings.cz

Professional
and certified lecturers

Internationally
recognized certifications

Wide range of technical
and soft skills courses

Great customer
service

Making courses
exactly to measure your needs

Course dates

Starting date: 08.01.2025

Type: Virtual

Course duration: 3 days

Language: en

Price without VAT: 1 600 EUR

Register

Starting date: Upon request

Type: Virtual

Course duration: 3 days

Language: en

Price without VAT: 1 600 EUR

Register

Starting
date
Place
Type Course
duration
Language Price without VAT
08.01.2025 Virtual 3 days en 1 600 EUR Register
Upon request Virtual 3 days en 1 600 EUR Register
G Guaranteed course

Didn't find a suitable date?

Write to us about listing an alternative tailor-made date.

Contact

Course structure

Module 1 – Implementing Splunk and SOAR
  • Review of SOAR UI and concepts
  • Describe interactions between Splunk and SOAR
  • Identify key concepts and data flows
  • Pre-requisites for integration
Module 2 – Configuring External Splunk Search
  • Describe the benefits of externalizing search to Splunk
  • Configure the SOAR instance for externalization
  • Configure the Splunk instance for externalization
  • Use the Splunk app for SOAR Reporting
Module 3 – Sending Splunk Events to SOAR
  • Configure the SOAR Add-on for Splunk
  • Map CIM fields to CEF
  • Send Enterprise Security notables to SOAR
  • Automatically trigger SOAR playbooks for Splunk notables
Module 4 – Accessing Splunk from SOAR
  • Install and configure the SOAR App for Splunk
  • Ingest Splunk events into SOAR
  • Use Splunk search from playbooks
  • Update Splunk notable events
Module 5 – Custom Coding in Playbooks
  • SOAR coding best practices
  • Writing, using and managing custom functions
  • Using the SOAR API in custom code
  • Store and retrieve persistent data
Module 6 – Using SOAR REST
  • Use Django queries to search for data in SOAR
  • Use REST to access SOAR data
  • Use the HTTP app to execute REST from playbooks

Prerequisites

Attendees for this class must ensure that they meet all course pre-requisites. This is a challenging, advanced class that draws on technical knowledge from many areas in Splunk and SOAR, and the demanding labs and course schedule leave little time to learn the basics.

Classes:

  • Experience with Python programming
  • Adminstering Splunk SOAR
  • Developing Splunk SOAR Playbooks
  • Enterprise Splunk Data Administration
  • Enterprise Splunk System Administration
  • Either Using or Administering Splunk Enterprise Security

Do you need advice or a tailor-made course?

onas

product support

Follow-up courses

Free Splunk Fundamentals 1 en

Vendor: Splunk

Area: Big Data

Price from

0 EUR without VAT

Free Splunk User Behavior Analytics en

Vendor: Splunk

Area: Big Data

Price from

0 EUR without VAT

Advanced Searching and Reporting en

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Splunk Infrastructure Overview en

Vendor: Splunk

Area: Big Data

Price from

0 EUR without VAT

Splunk for Analytics and Data Science en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Creating Dashboards with Splunk en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Splunk Cluster Administration en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Splunk Enterprise Data Administration en en/cz

Vendor: Splunk

Area: Big Data

Price from

2 395 EUR without VAT

Troubleshooting Splunk Enterprise en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Working with Metrics in Splunk en

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Implementing Splunk Data Stream Processor (DSP) en/cz

Vendor: Splunk

Area: Big Data

Price from

2 130 EUR without VAT

Splunk Cloud Administration en en/cz

Vendor: Splunk

Area: Big Data

Price from

2 125 EUR without VAT

Transitioning to Splunk Cloud en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Splunk Enterprise System Administration en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Advanced Dashboards and Visualizations en

Vendor: Splunk

Area: Big Data

Price from

535 EUR without VAT

Building Splunk Apps en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Developing with Splunk’s REST API en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Developing SOAR Playbooks en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Administering Splunk Enterprise Security en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Using Splunk Enterprise Security en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 600 EUR without VAT

Using Splunk IT Service Intelligence en

Vendor: Splunk

Area: Big Data

Price from

535 EUR without VAT

Implementing Splunk IT Service Intelligence en en/cz

Vendor: Splunk

Area: Big Data

Price from

2 135 EUR without VAT

Implementing Splunk SmartStore en

Vendor: Splunk

Area: Big Data

Price from

535 EUR without VAT

Vendor:

Area:

Price from

0 EUR without VAT

Price from

535 EUR without VAT

Using Splunk Observability Cloud Terraform Provider en en/cz

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

Using the Splunk Terraform Provider en

Vendor: Splunk

Area: Big Data

Price from

1 075 EUR without VAT

ComGate payment gateway MasterCard Logo Visa logo