Splunkのトレーニング + 認定
Administering Splunk Enterprise Security
- 無料コース
-
ラーニングパス
- ユーザー向けコース
- Splunk 管理者向けコース
- Splunk Cloud お客様向けコース
-
Splunk アーキテクト向けコース
- 概要
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- Creating Dashboards with Splunk
- Splunk Fundamentals 3
- Advanced Searching and Reporting
- Splunk Enterprise System Administration
- Splunk Enterprise Data Administration
- Troubleshooting Splunk Enterprise
- Splunk Enterprise Cluster Administration
- Architecting Splunk Enterprise Deployments
- Administering Splunk Enterprise Security
- アプリケーション開発者向けコース
- Enterprise Security 管理者向けコース
- Enterprise Security エンドユーザー向けコース
- IT Service Intelligence 管理者向けコース
- IT Service Intelligence エンドユーザー向けコース
- Phantom のお客様向けコース
- SignalFxのお客様向けコース
-
認定トラック
- Splunk Core Certified User
- Splunk Core Certified Power User
- Splunk Enterprise Certified Architect
- Splunk Enterprise Certified Admin
- Splunk Certified Developer
- Splunk Enterprise Security Certified Admin
- Splunk IT Service Intelligence Certified Admin
-
Splunk Core Certified Consultant
- 概要
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- Splunk Enterprise System Administration
- Splunk Enterprise Data Administration
- Architecting Splunk Enterprise Deployments
- Troubleshooting Splunk Enterprise
- Splunk Enterprise Cluster Administration
- Splunk Enterprise Practical Lab
- Creating Dashboards with Splunk
- Advanced Searching and Reporting
-
コース
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- Splunk Fundamentals 3
- Advanced Searching and Reporting
- Creating Dashboards with Splunk
- Advanced Dashboards and Visualizations
- Building Splunk Apps
- Splunk for Analytics and Data Science
- Splunk Infastructure Overview
- Splunk Enterprise System Administration
- Splunk Enterprise Data Administration
- Troubleshooting Splunk Enterprise
- Splunk Enterprise Cluster Administration
- Splunk Cloud Administration
- Architecting Splunk Enterprise Deployments
- Splunk Deployment Practical Lab
- Developing with Splunk's REST API
- Administering Splunk Enterprise Security
- Using Splunk Enterprise Security
- Implementing Splunk IT Service Intelligence
- Using Splunk IT Service Intelligence
- Splunk User Behavior Analytics
- Administering Phantom
- Working with Metrics in Splunk
- Developing Phantom Playbooks
- Implementing Splunk SmartStore
- Splunk Workload Management
- SignalFxの基礎シリーズ(Eラーニング)
- Infrastructure Monitoring Using SignalFx
- Sending Custom Metrics to SignalFx
- Advanced Monitoring of Microservices Applications Using SignalFx
- Automation Using the SignalFx API
- Using SignalFx to Monitor Microservices-based Applications
-
ビデオ
- All Videos
- Splunk Cloud Tutorial
- Installing Splunk Enterprise on Linux
- Installing Splunk Enterprise on Windows
- Getting Data In to Splunk Enterprise (Linux)
- Getting Data In (Windows)
- Getting Data In with Forwarders
- Basic Search in Splunk Enterprise
- Create a Dashboard in Splunk Enterprise
- Splunk Certification Candidate Journey
- Creating Alerts in Splunk Enterprise
-
- プログラムガイド & FAQ
- ファクトシートをダウンロード
Course Description
This 13.5 hour course prepares architects and systems administrators to install, configure and manage Splunk Enterprise Security. It covers ES event processing and normalization, deployment requirements, technology add-ons, settings, risk analysis settings, threat intelligence and protocol intelligence configuration, and customizations.
Instructor-led Training Schedule
Course Prerequisites
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- Splunk System Administration
- Splunk Data Administration
- Architecting Splunk Enterprise Deployments (recommended but not required)
Course Topics
- Monitoring and Investigation
- Security Intelligence
- Forensics, Glass Tables and Navigation Control
- ES Deployment
- Installation and Configuration
- Validating ES Data
- Custom Add-ons
- Tuning Correlation Searches
- Creating Correlation Searches
- Lookups and Identity Management
- Threat Intelligence Framework
Course Objectives
Module 1 – ES Introduction
- Overview of ES features and concepts
Module 2 – Monitoring and Investigation
- Security Posture
- Incident Review
- Notable events management
Module 3 – Security Intelligence
- Overview of security intel tools
Module 4 – Forensics, Glass Tables and Navigation Control
- Explore forensics dashboards
- Examine glass tables
- Configure navigation and dashboard permissions
Module 5 – ES Deployment
- Identify deployment topologies
- Examine the deployment checklist
- Understand indexing strategy for ES
- Understand ES Data Models
Module 6 – Installation and Configuration
- Prepare a Splunk environment for installation
- Download and install ES on a search head
- Test a new install
- Understand ES Splunk user accounts and roles
- Post-install configuration tasks
Module 7 – Validating ES Data
- Plan ES inputs
- Configure technology add-ons
Module 8 – Custom Add-ons
- Design a new add-on for custom data
- Use the Add-on Builder to build a new add-on
Module 9 – Tuning Correlation Searches
- Configure correlation search scheduling and sensitivity
- Tune ES correlation searches
Module 10 – Creating Correlation Searches
- Create a custom correlation search
- Configuring adaptive responses
- Search export/import
Module 11 – Lookups and Identity Management
- Identify ES-specific lookups
- Understand and configure lookup lists
Module 12 – Threat Intelligence Framework
- Understand and configure threat intelligence
- Configure user activity analysis