top of page
top

Investigating Incidents with Splunk SOAR

IISS

Investigating Incidents with Splunk SOAR

authorized-learning-partner.png

Price
Duration

On Request

1 Day

Courses
PDF Outline
PDF Outline

Prerequisites

Prerequisits

• Basic security operations knowledge

What you'll will learn

What you’ll learn in this course

This course prepares security practitioners to use SOAR to respond to security incidents,

investigate vulnerabilities, and take action to mitigate and prevent security problems.

Objectives

Course Objectives

Course Outline

Outlines
PDF Outline

Topic 1 – Starting Investigations
• SOAR investigation concepts
• ROI view
• Using the Analyst Queue
• Using indicators
• Using search
Topic 2 – Working on Events
• Use the Investigation page to work on events
• Use the heads-up display
• Set event status and other fields
• Use notes and comments
• How SLA affects event workflow
• Using artifacts and files
• Exporting events
• Executing actions and playbooks
• Managing approvals

Topic 3 – Cases: Complex Events
• Use case management for complex investigations
• Use case workflows
• Mark evidence
• Running reports

reg1

Further information

If you would like to know more about this course please contact us

Schedule
authorized-learning-partner.png
For dates in South Africa and Africa region 

Thanks for registering. our team will contact you soon !

Registration

ILT/VILT
bottom of page