The Splunk Enterprise Security Certified Admin (SPLK-3001) course prepares security administrators and SOC professionals to deploy, configure, and manage Splunk Enterprise Security in enterprise environments. Students gain hands-on experience with correlation searches, notable events, threat intelligence, risk-based alerting, incident investigations, and security content management while preparing for the SPLK-3001 certification.
Curriculum
- 12 Sections
- 0 Lessons
- 12 Weeks
Expand all sectionsCollapse all sections
- Week 1: Splunk Enterprise Security Architecture & Deployment0
- Week 2: Security Content & Data Onboarding0
- Week 3: Correlation Searches & Notable Events0
- Week 4: Incident Review & Investigation Workflows0
- Week 5: Threat Intelligence Framework0
- Week 6: Risk-Based Alerting (RBA) & Risk Analysis0
- Week 7: Asset & Identity Framework0
- Week 8: Dashboards, Reports & Security Analytics0
- Week 9: Performance Tuning & Troubleshooting0
- Week 10: Administration, Upgrades & Best Practices0
- Week 11: Hands-On Labs & Enterprise Security Scenarios0
- Week 12: Final Review & Certification Exam Preparation0