Splunk Enterprise Security SIEM Operations Training Course
| Course code | SD-CS-003 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent credible risk, investigate them quickly, document decisions, and improve the content that drives their SIEM. Splunk Enterprise Security (ES) provides correlation searches, notable events, risk-based alerting, threat intelligence, investigation workspaces, and reporting, but these capabilities only reduce exposure when analysts and SIEM operators configure and use them consistently. This course addresses the operational gap between receiving alerts and producing defensible incident outcomes.
Participants learn to operate Splunk Enterprise Security as a working SOC platform. They build searches with SPL, navigate the Incident Review workflow, triage notable events, investigate entities and assets, apply adaptive response actions, tune correlation searches, manage lookups and threat-intelligence sources, and use risk scores to prioritise work. The course also covers data quality checks, analyst workflow design, MITRE ATT&CK mapping, dashboard interpretation, and the practical governance needed to prevent alert fatigue while retaining useful detection coverage.
Delivery combines instructor-led demonstrations with a dedicated Splunk lab environment populated with realistic endpoint, authentication, network, cloud, and threat-intelligence data. Participants investigate simulated incidents, refine noisy detections, and work through escalation decisions using evidence from ES. Each participant leaves with a documented SIEM operations playbook containing triage criteria, investigation queries, correlation-search tuning decisions, dashboard measures, and a 30-day improvement plan that can be adapted to their own SOC.
The course is suited to security analysts, SOC leads, SIEM engineers, incident responders, and IT operations staff moving into security monitoring responsibilities. It is equally valuable to managers who need staff to establish measurable, sustainable Splunk ES operating practices rather than rely on ad hoc alert handling.
Course objectives
By the end of this course, participants will be able to:
- Configure Splunk Enterprise Security navigation, roles, data models, and asset and identity context for daily SOC operations
- Write SPL searches that pivot from notable events to authentication, endpoint, network, and cloud evidence
- Triage notable events in Incident Review using severity, urgency, risk score, asset criticality, and threat-intelligence context
- Investigate security incidents with the ES Investigation workbench and produce an evidence-based case timeline
- Tune correlation searches by analysing false positives, adjusting thresholds, filtering exceptions, and documenting detection rationale
- Build and validate risk-based alerting workflows that aggregate risk events across users, systems, and detections
- Manage threat-intelligence lookups and map detections to MITRE ATT&CK techniques for coverage reporting
- Produce a SIEM operations playbook with escalation criteria, investigation queries, operational metrics, and a 30-day improvement plan
Benefits of attending
For you
- Gain practical evidence of competence operating Splunk ES beyond basic dashboard monitoring
- Develop reusable SPL investigation queries for authentication, endpoint, network, and threat-intelligence pivots
- Improve credibility when recommending alert closures, escalations, threshold changes, and detection exceptions
- Build the ability to translate MITRE ATT&CK coverage gaps into actionable Splunk ES detection improvements
- Leave with a portfolio-ready SIEM operations playbook and 30-day improvement plan for a current or future SOC role
For your organisation
- Reduce analyst time spent on low-value alerts through structured correlation-search tuning and documented exceptions
- Improve incident triage consistency by applying shared severity, urgency, risk, asset, and intelligence criteria
- Increase detection accountability through correlation-search ownership, ATT&CK mapping, and measurable coverage reporting
- Strengthen auditability with documented investigation timelines, escalation decisions, and operational playbooks
- Create a practical backlog of Splunk ES data-quality, dashboard, detection, and workflow improvements for the SOC
Target competencies
Who should attend
- SOC Analysts — who triage Splunk ES notable events and need consistent investigation and escalation methods
- SIEM Engineers — who configure, tune, and maintain Splunk Enterprise Security detection content and data context
- Incident Responders — who need to pivot from alerts into validated evidence, timelines, and containment decisions
- SOC Team Leads — who need measurable analyst workflows, alert-quality controls, and detection governance
- Cyber Security Engineers — who integrate telemetry, threat intelligence, and response actions into the security monitoring stack
- IT Operations Analysts — who are taking responsibility for security event monitoring and first-line incident investigation
Requirements and prerequisites
Participants should understand basic cyber security concepts, including logs, authentication events, IP addresses, hostnames, common attack stages, and incident severity. Familiarity with a SIEM or monitoring console is helpful, and attendees should be able to interpret simple search results and CSV-style fields. Prior exposure to Splunk Enterprise or basic SPL searching is beneficial but not mandatory; the course introduces the SPL patterns used in the labs. No Splunk administration certification, coding background, threat-hunting experience, or prior use of Splunk SOAR is required. Complete beginners should expect a technically focused week with guided lab practice.
Training methodology
The five-day course alternates focused instructor demonstrations with guided work in a Splunk Enterprise Security lab. Participants work with realistic authentication, endpoint, firewall, cloud, and threat-intelligence events rather than isolated commands. Exercises require them to triage notable events, run SPL pivots, create investigation timelines, tune correlation searches, and assess risk-based alerting. Small-group case reviews compare escalation decisions and tuning trade-offs. On the final day, each participant consolidates their lab work into an operational playbook and prioritised 30-day improvement plan for their own environment.
Course outline
Day 1: Splunk ES architecture and SOC operating model
- Splunk Enterprise Security architecture, apps, roles, and knowledge objects
- Security data onboarding concepts, CIM normalisation, and data-model acceleration
- Asset and identity framework configuration for investigation context
- Splunk ES navigation, dashboards, security posture, and analyst work queues
- Notable events, correlation searches, adaptive response actions, and Incident Review relationships
- SPL foundations for field extraction, filtering, aggregation, and time-based analysis
- SOC triage workflow design using severity, urgency, asset criticality, and ownership
Workshop: Participants inspect a populated ES environment and produce a first-line triage workflow for a set of authentication and endpoint notable events.
Day 2: Notable event triage and incident investigation
- Incident Review filters, status management, event assignment, and disposition codes
- Investigative pivots from a notable event into raw events and data-model datasets
- SPL techniques for user, host, IP address, process, and time-window correlation
- Investigation workbench timelines, annotations, and evidence management
- Entity investigation using asset, identity, risk, and threat-intelligence context
- Authentication attack analysis for brute force, impossible travel, and privileged account misuse
- Escalation thresholds and evidence requirements for security incident handover
Workshop: Participants investigate a suspected account compromise and produce an incident timeline, evidence summary, and escalation recommendation.
Day 3: Detection engineering and correlation search tuning
- Correlation search anatomy, scheduling, throttling, suppression, and notable event fields
- Detection tuning methods using baseline behaviour, thresholds, allow lists, and exception logic
- False-positive analysis with search sampling, field validation, and source-data checks
- Lookup tables, KV Store collections, macros, and reusable detection enrichment
- Risk-based alerting concepts, risk modifiers, risk objects, and aggregation logic
- MITRE ATT&CK technique mapping for correlation searches and detection coverage
- Detection lifecycle governance including testing, approval, ownership, and change records
Workshop: Participants tune a noisy lateral-movement correlation search and produce a documented detection change record with before-and-after results.
Day 4: Threat intelligence, dashboards, and response workflows
- Threat-intelligence frameworks, intelligence sources, and indicator confidence assessment
- Threat activity lookup generation and indicator matching in Splunk ES
- Intel-based detections for malicious IP addresses, domains, hashes, and URLs
- Adaptive response actions and integration patterns with Splunk SOAR
- Security dashboard design for alert volume, triage ageing, detection quality, and risk trends
- SOC operational metrics including mean time to acknowledge, closure reasons, and false-positive rate
- Data-quality monitoring for sourcetypes, field extractions, CIM alignment, and ingestion gaps
Workshop: Participants create a threat-intelligence-driven investigation workflow and draft a SOC dashboard specification with five operational measures.
Day 5: SIEM operations governance and applied improvement planning
- Daily, weekly, and monthly Splunk ES operating routines
- Alert queue management, analyst handover, case notes, and escalation service levels
- Use-case prioritisation based on risk, telemetry quality, ATT&CK coverage, and investigation cost
- Detection health reviews and correlation-search performance monitoring
- Incident lessons learned translated into new searches, tuning tasks, and data requirements
- SIEM governance roles for analysts, engineers, platform owners, and SOC management
- 30-day Splunk ES improvement roadmap planning and stakeholder reporting
Workshop: Participants complete and present a Splunk ES operations playbook and prioritised 30-day improvement plan based on the week's simulated SOC cases.
Tools & standards covered
Splunk Enterprise Security, Splunk Enterprise, Splunk SOAR, MITRE ATT&CK
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Dubai · USD 4,500 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Dubai · USD 4,500 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200 -
16 – 20 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Risk Oversight for Board Directors Training Course
Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …
Wireshark Network Packet Analysis Training Course
Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …
Palo Alto Cortex XSOAR Security Automation Playbooks Training Course
Security operations teams often lose critical time moving alerts between SIEM, EDR, threat-intelligence, ticketing and messaging tools. Anal…
NIST Cybersecurity Framework Implementation Training Course
Organisations often have security controls, policies, audit findings and risk registers in separate places, yet cannot clearly show how thos…