Administering Splunk SOAR (ASOAR)

 

Course Overview

This 3 hour course prepares IT professionals to configure and manage SOAR.

Who should attend

IT and security practitioners, developers.

Certifications

This course is part of the following Certifications:

Prerequisites

Investigating Incidents with Splunk SOAR

Course Objectives

  • SOAR concepts
  • Initial configuration
  • Apps and assets
  • Configuring automation
  • User management
  • Ingesting data
  • Customization and monitoring

Outline: Administering Splunk SOAR (ASOAR)

Topic 1 –Initial Configuration

  • Describe SOAR operating concepts
  • Identify documentation and community resources
  • SOAR & Splunk Architecture
  • Product settings
  • Access control
  • Authentication settings
  • Response settings
  • Understanding roles
  • Creating users
  • Managing user access
  • Describe SOAR Automation Broker

Topic 2 – Apps, Assets and Playbooks

  • Add and configure apps and assets
  • Manage playbooks
  • Ingesting Data
  • Labels and tags
  • Event settings

Topic 3 – Customization and Monitoring

  • Create custom severity levels
  • Create custom status levels
  • Add custom fields and CEF settings
  • Create custom workbooks
  • Run reports
  • Use SOAR audit tools
  • Monitor system health

Appendix: SOAR Automation Broker

Prices & Delivery methods

Online Training

Duration
3 hours

Price
  • Online Training: CAD 690
  • Online Training: US $ 500
  • Splunk Training Units: 50 SPC
Classroom Training

Duration
3 hours

Price
  • Canada: CAD 690
  • Splunk Training Units: 50 SPC

Click on town name or "Online Training" to book Schedule

Guaranteed date:   We will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training. If you have any questions about our online courses, feel free to contact us via phone or Email anytime.
*   This class is delivered by a vendor or third party partner.

United States

Online Training 09:00 Eastern Daylight Time (EDT) * Enroll
Online Training 09:00 Pacific Daylight Time (PDT) * Enroll
Online Training 09:00 Eastern Daylight Time (EDT) * Enroll
Online Training 09:00 Pacific Daylight Time (PDT) * Enroll
Online Training 09:00 Pacific Daylight Time (PDT) * Enroll
Online Training 09:00 Pacific Daylight Time (PDT) * Enroll
Online Training 09:00 Eastern Daylight Time (EDT) Enroll
Online Training 09:00 Eastern Standard Time (EST) Enroll

Canada

Online Training 09:00 Eastern Daylight Time (EDT) Enroll
Online Training 09:00 Eastern Standard Time (EST) Enroll