Administering Splunk SOAR 5.5

Administering Splunk SOAR 5.5

Upcoming Classes

No classes have been scheduled.

Summary

This 3 hour course prepares IT professionals to configure and manage SOAR.

Description

  • SOAR concepts
  • Initial configuration
  • Apps and assets
  • Configuring automation
  • User management
  • Ingesting Data
  • Customization and monitoring

Duration

3 hours

Objectives

Topic 1 –Initial Configuration
  • Describe SOAR operating concepts
  • Identify documentation and community resources
  • SOAR & Splunk Architecture
  • Product settings
  • Access control
  • Authentication settings
  • Response settings
  • Understanding roles
  • Creating users
  • Managing user access
  • Describe SOAR Automation Broker

Topic 2 – Apps, Assets and Playbooks
  • Add and configure apps and assets
  • Manage playbooks
  • Ingesting Data
  • Labels and tags
  • Event settings

Topic 3 – Customization and Monitoring
  • Create custom severity levels
  • Create custom status levels
  • Add custom fields and CEF settings
  • Create custom workbooks
  • Run reports
  • Use SOAR audit tools
  • Monitor system health

Appendix: SOAR Automation Broker

Prerequisites

Classes:

  • Investigating Incidents with Splunk SOAR

 

Onsite Training

For groups of three or more

Request Quote

Public Training