logo
Courses
    logo
  • Courses
  • Corporate Training
  • Testimonials

Splunk Enterprise Security Administration Course

Structured path to run Splunk ES confidently

Configure roles, inputs, access controls, and governance

Build correlation searches and notable events that matter

Triage incidents faster using response workflows and playbooks

Produce stakeholder-ready dashboards and security reporting

Instructor-led delivery aligned with certification expectations

GoogleGoogle4.6/5
3500 EnrolledEnrolled Learners
GoogleGoogle4.6/5
3500 EnrolledEnrolled Learners

Overview

What our training includes:

  • Splunk Enterprise Security Administration course: learn ES setup, access, and navigation
  • Configure users, roles, and permissions to control SOC workflows
  • Build correlation searches and notable events for stronger threat visibility
  • Tune detections, risk scoring, and threat lists to reduce noise
  • Manage assets and identities using lookups, KV Store, and LDAP feeds
  • Create dashboards and incident workflows for job-ready SOC operations

Upcoming sessions

Curriculum

1

Explain the function of a SIEM

2

Give an overview of Splunk’s Enterprise Security (ES)

3

Describe detections and findings

4

Configure ES roles and permissions

5

Give an overview of ES navigation

1

Provide an overview of the Analyst Queue

2

Create and use Analyst Queue Views

3

Customise the Analyst Queue

4

Modify Urgency

5

Create new Status values

6

Add fields to Finding attributes

7

Create ad hoc Findings

8

Suppress Findings

1

Give an overview of an investigation

2

Use and create Response Plans

3

Add Splunk events to an investigation

4

Use Playbooks and Actions

1

Review the Asset and Identity Management interface

2

Describe Asset and Identity KV Store collections

3

Configure and add asset and identity lookups to the interface

4

Configure settings and fields for asset and identity lookups

5

Explain the asset and identity merge process

1

Understand how ES uses accelerated data models

2

Verify data is correctly configured for use in ES

3

Validate normalisation configurations

4

Install additional add-ons

5

Ingest custom data in ES

6

Create an add-on for a custom sourcetype

7

Describe add-on troubleshooting

1

Give an overview of how to create Event-based detections

2

Review the Detection Editor

3

Give an overview of how to create Finding-based detections

1

Give an overview of Risk-Based Alerting (RBA)

2

Explain risk scores and how they can be changed by detections or manually

3

Review the Risk analysis dashboard

4

Understand Finding-based detections

5

Describe annotations

6

View risk information in Analyst Queue findings

1

Understand and configure threat intelligence

2

Use the Threat Intelligence interface to configure threat lists

3

Configure new threat lists

1

Give an overview of general ES install requirements

2

Explain the different add-ons and where they are installed

3

Provide ES pre-installation requirements

4

Describe the Splunk_TA_ForIndexers app and where it is installed

5

Set general configuration options

6

Configure local and cloud domain information

7

Work with the Incident Review KV Store

8

Customise navigation

9

Configure Key Indicator searches

Meet your Trainer

Our Trainers

Learners Point has a reputation for high-quality training that makes a difference in people's lives. We undertake a practical and innovative approach to working closely with businesses to improve their workforce. Our expertise is wide-ranging with ample support from our expert trainers who are globally recognized and hold a diverse set of experiences in their field of expertise. We are proud of our instructors who take ownership of our distinctive and comprehensive training methodologies, help our students imbibe those with ease, and accomplish gracefully.

We at Learners Point believe in encouraging our students to embark upon a journey of lifelong learning and self-development, with the aid of our comprehensive and distinctive courses tailored to current market trends. The manifestation of our career-oriented approach is what we assure through a pleasant professional enriched environment with cutting-edge technology, and an outstanding while highly acknowledged training staff that uses up-to-date methodologies and quality course material. With our aim to mold professionals to be future leaders, our industry expert trainers provide the best in town mentorship to our students while endowing them with the thirst for knowledge and inspiring them to strive for professional and human excellence.

Our Trainers

Learning Outcomes

After completion of the course, you will master the following:

  • 1

    Master Splunk Enterprise Security Administration course learning path from setup to operations.

  • 2

    Configure users, roles, and access controls for governed security operations.

  • 3

    Build correlation searches and notables to detect threats across data.

  • 4

    Tune detections and reduce alert noise using prioritisation and thresholds.

  • 5

    Triage incidents with response workflows and playbooks for faster closure.

  • 6

    Create dashboards and security reports for stakeholders and audit evidence.

  • objective-image

    Ready to get started?

  • Learners Point Certificate

    Earn a Course Completion Certificate, an official Learners Point credential that confirms that you have successfully completed a course with us.

    Certifcate-Image0

    Overall ratings by our students

    Related courses

    Frequently asked questions

    The Splunk Enterprise Security Administration course is an administrator-focused program that prepares participants to run Splunk Enterprise Security (ES) in a SOC environment. It covers ES navigation, role-based access control, Analyst Queue configuration, investigations, asset and identity administration, data normalisation checks, detection engineering, risk-based alerting, threat intelligence management, and post-deployment configuration. The learning path is built around operational governance, consistent triage workflows, and reliable reporting that supports day-to-day security operations.

    This course is most relevant for professionals responsible for Splunk ES operations and SIEM governance, including:

    • SOC Analysts handling findings and investigations
    • SOC Engineers supporting ES configuration and workflows
    • SIEM Administrators managing roles, add-ons, and data readiness
    • Detection/Content Engineers tuning detections and risk scoring
    • Security Operations Leads overseeing platform performance and reporting

    Participants can demonstrate job-relevant ES administration capability, including:

    • Configure ES roles, permissions, and navigation settings
    • Customise Analyst Queue views, urgency, and status values
    • Create, suppress, and manage findings for cleaner triage
    • Build investigations using response plans, playbooks, and actions
    • Administer assets and identities using KV Store, lookups, and LDAP feeds
    • Create and tune detections; apply risk-based alerting and annotations
    • Configure and manage threat intelligence lists for enrichment

    The course supports progression into SIEM and SOC platform ownership roles, such as:

    • Splunk Enterprise Security Administrator
    • SIEM Engineer / SIEM Administrator
    • SOC Engineer / SOC Platform Engineer
    • Detection Engineer / Content Engineer
    • SOC Analyst (Tier 2 pathway)
    • Security Operations Lead (platform-focused)

    The learning path follows the ES administrator journey:

    • ES overview, navigation, roles, and permissions
    • Analyst Queue configuration and findings control
    • Investigation workflows with response plans and actions
    • Asset & identity management, lookups, KV Store, LDAP enrichment
    • Data normalisation checks, add-ons, and custom data onboarding
    • Detection engineering using Detection Editor
    • Risk-based alerting and risk analysis
    • Threat intelligence configuration and threat lists
    • Post-deployment configuration and operational governance

    Alert volume is controlled through configuration choices that standardise triage. Participants learn how to build queue views, adjust urgency and status logic, add consistent finding attributes, and apply suppression where appropriate.

    Tuning is strengthened through detection engineering and risk-based alerting, including risk scoring and annotations that help prioritise meaningful activity. Threat intelligence list management also improves contextual accuracy, so investigations start with a better signal.

    Splunk certifications typically follow a three-year validity cycle. For long-term capability planning, it helps to treat certification as part of an ongoing SOC skills program, with periodic refresh and structured revision. Renewal planning is especially useful for enterprise teams managing handovers, role changes, and shift-based coverage.

    Many generic providers focus heavily on Splunk search, dashboards, and broad administration. This course is more tightly aligned to Enterprise Security operations: Analyst Queue governance, investigations with response plans and playbooks, asset/identity enrichment using KV Store and LDAP, detection engineering, risk-based alerting, threat intelligence lists, and post-deployment configuration tasks. That ES-specific depth is what strengthens SOC readiness, not just platform familiarity.

    Do you want to learn more about Learners Point Academy?

    • Learn more about courses
    • Understand about our methodology
    • Let’s talk about Corporate trainings
    • Anything else that you want to know, we are here for you!

    Let's chat!

    • Afghanistan+93
    • Albania+355
    • Algeria+213
    • Andorra+376
    • Angola+244
    • Antigua and Barbuda+1268
    • Argentina+54
    • Armenia+374
    • Aruba+297
    • Australia+61
    • Austria+43
    • Azerbaijan+994
    • Bahamas+1242
    • Bahrain+973
    • Bangladesh+880
    • Barbados+1246
    • Belarus+375
    • Belgium+32
    • Belize+501
    • Benin+229
    • Bhutan+975
    • Bolivia+591
    • Bosnia and Herzegovina+387
    • Botswana+267
    • Brazil+55
    • British Indian Ocean Territory+246
    • Brunei+673
    • Bulgaria+359
    • Burkina Faso+226
    • Burundi+257
    • Cambodia+855
    • Cameroon+237
    • Canada+1
    • Cape Verde+238
    • Caribbean Netherlands+599
    • Cayman Islands+1
    • Central African Republic+236
    • Chad+235
    • Chile+56
    • China+86
    • Colombia+57
    • Comoros+269
    • Congo+243
    • Congo+242
    • Costa Rica+506
    • Côte d'Ivoire+225
    • Croatia+385
    • Cuba+53
    • Curaçao+599
    • Cyprus+357
    • Czech Republic+420
    • Denmark+45
    • Djibouti+253
    • Dominica+1767
    • Dominican Republic+1
    • Ecuador+593
    • Egypt+20
    • El Salvador+503
    • Equatorial Guinea+240
    • Eritrea+291
    • Estonia+372
    • Ethiopia+251
    • Fiji+679
    • Finland+358
    • France+33
    • French Guiana+594
    • French Polynesia+689
    • Gabon+241
    • Gambia+220
    • Georgia+995
    • Germany+49
    • Ghana+233
    • Greece+30
    • Greenland+299
    • Grenada+1473
    • Guadeloupe+590
    • Guam+1671
    • Guatemala+502
    • Guinea+224
    • Guinea-Bissau+245
    • Guyana+592
    • Haiti+509
    • Honduras+504
    • Hong Kong+852
    • Hungary+36
    • Iceland+354
    • India+91
    • Indonesia+62
    • Iran+98
    • Iraq+964
    • Ireland+353
    • Israel+972
    • Italy+39
    • Jamaica+1876
    • Japan+81
    • Jordan+962
    • Kazakhstan+7
    • Kenya+254
    • Kiribati+686
    • Kosovo+383
    • Kuwait+965
    • Kyrgyzstan+996
    • Laos+856
    • Latvia+371
    • Lebanon+961
    • Lesotho+266
    • Liberia+231
    • Libya+218
    • Liechtenstein+423
    • Lithuania+370
    • Luxembourg+352
    • Macau+853
    • Macedonia+389
    • Madagascar+261
    • Malawi+265
    • Malaysia+60
    • Maldives+960
    • Mali+223
    • Malta+356
    • Marshall Islands+692
    • Martinique+596
    • Mauritania+222
    • Mauritius+230
    • Mexico+52
    • Micronesia+691
    • Moldova+373
    • Monaco+377
    • Mongolia+976
    • Montenegro+382
    • Morocco+212
    • Mozambique+258
    • Myanmar+95
    • Namibia+264
    • Nauru+674
    • Nepal+977
    • Netherlands+31
    • New Caledonia+687
    • New Zealand+64
    • Nicaragua+505
    • Niger+227
    • Nigeria+234
    • North Korea+850
    • Norway+47
    • Oman+968
    • Pakistan+92
    • Palau+680
    • Palestine+970
    • Panama+507
    • Papua New Guinea+675
    • Paraguay+595
    • Peru+51
    • Philippines+63
    • Poland+48
    • Portugal+351
    • Puerto Rico+1
    • Qatar+974
    • Réunion+262
    • Romania+40
    • Russia+7
    • Rwanda+250
    • Saint Kitts and Nevis+1869
    • Saint Lucia+1758
    • Saint Vincent and the Grenadines+1784
    • Samoa+685
    • San Marino+378
    • São Tomé and Príncipe+239
    • Saudi Arabia+966
    • Senegal+221
    • Serbia+381
    • Seychelles+248
    • Sierra Leone+232
    • Singapore+65
    • Slovakia+421
    • Slovenia+386
    • Solomon Islands+677
    • Somalia+252
    • South Africa+27
    • South Korea+82
    • South Sudan+211
    • Spain+34
    • Sri Lanka+94
    • Sudan+249
    • Suriname+597
    • Swaziland+268
    • Sweden+46
    • Switzerland+41
    • Syria+963
    • Taiwan+886
    • Tajikistan+992
    • Tanzania+255
    • Thailand+66
    • Timor-Leste+670
    • Togo+228
    • Tonga+676
    • Trinidad and Tobago+1868
    • Tunisia+216
    • Turkey+90
    • Turkmenistan+993
    • Tuvalu+688
    • Uganda+256
    • Ukraine+380
    • United Arab Emirates+971
    • United Kingdom+44
    • United States+1
    • Uruguay+598
    • Uzbekistan+998
    • Vanuatu+678
    • Vatican City+39
    • Venezuela+58
    • Vietnam+84
    • Yemen+967
    • Zambia+260
    • Zimbabwe+263

    Learn now, pay later

    Dive into your course now and pay in installments

    Tamara
    ADCB