Administering SOAR (ASOAR)

 

Course Overview

This 3 hour course prepares IT professionals to configure and manage SOAR.

Who should attend

IT and security practitioners, developers.

Certifications

This course is part of the following Certifications:

Prerequisites

Investigating Incidents with Splunk

Course Objectives

  • SOAR modules and concepts
  • Installation
  • Initial configuration
  • Apps and assets
  • User management
  • Ingesting data
  • Investigations
  • Running actions and playbooks
  • Case management & workflows
  • Multi-tenancy & clustering

Outline: Administering SOAR (ASOAR)

Topic 1 –Initial Configuration

  • Describe SOAR operating concepts
  • Identify documentation and community resources
  • SOAR & Splunk Architecture
  • Product settings
  • Access control
  • Authentication settings
  • Response settings
  • Understanding roles
  • Creating users
  • Managing user access

Topic 2 – Apps, Assets and Playbooks

  • Add and configure apps and assets
  • Manage playbooks
  • Ingesting Data
  • Labels and tags
  • Event settings

Topic 3 – Customization and Monitoring

  • Create custom severity levels
  • Create custom status levels
  • Add custom fields and CEF settings
  • Create custom workbooks
  • Run reports
  • Use SOAR audit tools
  • Monitor system health

Prices & Delivery methods

Online Training

Duration
3 hours

Price
  • Online Training: CAD 1,270
  • Online Training: US$ 500
  • Splunk Training Units: 50 SPC
Classroom Training

Duration
3 hours

Price
  • Canada: CAD 1,270
  • Splunk Training Units: 50 SPC

Click on town name or "Online Training" to book Schedule

This is an Instructor-Led Classroom course
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.
This is a FLEX course, which is delivered both virtually and in the classroom.
*   This class is delivered by a partner.

United States

Online Training 09:00 US/Pacific * Enroll
Online Training 09:00 US/Eastern * Enroll
Online Training 09:00 US/Pacific * Enroll
Online Training 09:00 US/Eastern * Enroll
Online Training 09:00 US/Eastern * Enroll
Online Training 09:00 US/Pacific * Enroll
Online Training 09:00 US/Eastern * Enroll
Online Training 09:00 US/Pacific * Enroll
Online Training 09:00 US/Pacific * Enroll
Online Training 09:00 US/Eastern * Enroll