Structured path to run Splunk ES confidently
Configure roles, inputs, access controls, and governance
Build correlation searches and notable events that matter
Triage incidents faster using response workflows and playbooks
Produce stakeholder-ready dashboards and security reporting
Instructor-led delivery aligned with certification expectations
What our training includes:
Upcoming sessions
Explain the function of a SIEM
Give an overview of Splunk’s Enterprise Security (ES)
Describe detections and findings
Configure ES roles and permissions
Give an overview of ES navigation
Provide an overview of the Analyst Queue
Create and use Analyst Queue Views
Customise the Analyst Queue
Modify Urgency
Create new Status values
Add fields to Finding attributes
Create ad hoc Findings
Suppress Findings
Give an overview of an investigation
Use and create Response Plans
Add Splunk events to an investigation
Use Playbooks and Actions
Review the Asset and Identity Management interface
Describe Asset and Identity KV Store collections
Configure and add asset and identity lookups to the interface
Configure settings and fields for asset and identity lookups
Explain the asset and identity merge process
Understand how ES uses accelerated data models
Verify data is correctly configured for use in ES
Validate normalisation configurations
Install additional add-ons
Ingest custom data in ES
Create an add-on for a custom sourcetype
Describe add-on troubleshooting
Give an overview of how to create Event-based detections
Review the Detection Editor
Give an overview of how to create Finding-based detections
Give an overview of Risk-Based Alerting (RBA)
Explain risk scores and how they can be changed by detections or manually
Review the Risk analysis dashboard
Understand Finding-based detections
Describe annotations
View risk information in Analyst Queue findings
Understand and configure threat intelligence
Use the Threat Intelligence interface to configure threat lists
Configure new threat lists
Give an overview of general ES install requirements
Explain the different add-ons and where they are installed
Provide ES pre-installation requirements
Describe the Splunk_TA_ForIndexers app and where it is installed
Set general configuration options
Configure local and cloud domain information
Work with the Incident Review KV Store
Customise navigation
Configure Key Indicator searches
After completion of the course, you will master the following:
1
Master Splunk Enterprise Security Administration course learning path from setup to operations.
2
Configure users, roles, and access controls for governed security operations.
3
Build correlation searches and notables to detect threats across data.
4
Tune detections and reduce alert noise using prioritisation and thresholds.
5
Triage incidents with response workflows and playbooks for faster closure.
6
Create dashboards and security reports for stakeholders and audit evidence.
Overall ratings by our students
The Splunk Enterprise Security Administration course is an administrator-focused program that prepares participants to run Splunk Enterprise Security (ES) in a SOC environment. It covers ES navigation, role-based access control, Analyst Queue configuration, investigations, asset and identity administration, data normalisation checks, detection engineering, risk-based alerting, threat intelligence management, and post-deployment configuration. The learning path is built around operational governance, consistent triage workflows, and reliable reporting that supports day-to-day security operations.
This course is most relevant for professionals responsible for Splunk ES operations and SIEM governance, including:
Participants can demonstrate job-relevant ES administration capability, including:
The course supports progression into SIEM and SOC platform ownership roles, such as:
The learning path follows the ES administrator journey:
Alert volume is controlled through configuration choices that standardise triage. Participants learn how to build queue views, adjust urgency and status logic, add consistent finding attributes, and apply suppression where appropriate.
Tuning is strengthened through detection engineering and risk-based alerting, including risk scoring and annotations that help prioritise meaningful activity. Threat intelligence list management also improves contextual accuracy, so investigations start with a better signal.
Splunk certifications typically follow a three-year validity cycle. For long-term capability planning, it helps to treat certification as part of an ongoing SOC skills program, with periodic refresh and structured revision. Renewal planning is especially useful for enterprise teams managing handovers, role changes, and shift-based coverage.
Many generic providers focus heavily on Splunk search, dashboards, and broad administration. This course is more tightly aligned to Enterprise Security operations: Analyst Queue governance, investigations with response plans and playbooks, asset/identity enrichment using KV Store and LDAP, detection engineering, risk-based alerting, threat intelligence lists, and post-deployment configuration tasks. That ES-specific depth is what strengthens SOC readiness, not just platform familiarity.
Learn now, pay later
Dive into your course now and pay in installments

