BR Treinamentos
ECSS Security & Cybersecurity

Enhancing Cisco Security Solutions with Splunk

40 horas Nível: Profissional Presencial (SP) e Online

Introdução

The Enhancing Cisco Security Solutions with Splunk (ECSS) training covers intermediate-level knowledge of Splunk to detect, investigate, and respond to security threats, including Splunk Enterprise, SIEM, SOAR, and Cisco security integrations.

Objetivo do curso

Explain Splunk Enterprise/Cloud fundamentals

Explain SIEM and SOAR as part of modern SOC architecture

Implement Cisco Security Solutions to Splunk Integration using Cisco Security Cloud App

Implement Cisco Security Solutions to Splunk Integration using Cisco Legacy Apps and TAs

Illustrate the value of integrating Cisco security solutions with Splunk

Troubleshoot the Cisco Security Cloud App and Cisco Apps and TAs

Público-alvo

System Engineers, SOC Engineers

Pré-requisitos

No formal prerequisites. Recommended: Cisco CCNP Security or equivalent knowledge.

Conteúdo programático

Course Outline
Overview of Splunk Enterprise and Splunk Cloud
Splunk Enterprise and Cloud Components
Splunk Enterprise Data Ingestion
Splunk Search Programming Language
Splunk Dashboards and Reports
XDR, SIEM, and SOAR Platforms
Cisco XDR, Splunk SIEM, and Splunk SOAR
Cisco Security Cloud App
Cisco Secure Firewall Integration
Cisco Splunk Enterprise Integration
Cisco Secure Malware Analytics, Duo, Secure Network Analytics, Email Threat Defense Integrations
Cisco Security Legacy Apps and TAs
Cisco ISE Integration
Cisco NVM Integration
Cisco Security Solutions and Splunk Use Case
Troubleshoot General Splunk Issues
Troubleshoot Cisco Security Cloud App
Troubleshoot Cisco Legacy Apps and Add-ons

Lab Outline
Explore Splunk Indexes
Verify and Test Data Ingestion
Perform Search Queries
Create Dashboards and Reports
Explore Splunk SOAR
Explore Cisco XDR Incident Investigation
Cisco Secure Firewall Integration with Splunk
Cisco Duo Integration Simulation
Cisco SNA Integration Simulation
Explore Cisco ISE Integration with Splunk
Explore Cisco NVM Integration with Splunk
Investigate Ransomware Using Splunk with Cisco Security Apps
Troubleshoot Cisco Security Cloud App
Troubleshoot Cisco ISE and NVM Integration with Splunk

Cursos relacionados

Próximas turmas

Não há turmas abertas no momento. Entre em contato para verificar disponibilidade ou agendar turma fechada.

Solicitar Inscrição / Cotação Consultar via WhatsApp