The Enhancing Cisco Security Solutions with Splunk (ECSS) course covers intermediate-level knowledge of Splunk, including its fundamentals, key components, and architecture so you can detect, investigate, and respond to security threats effectively. You’ll learn to utilize various Splunk components, including Cisco XDR, Splunk SIEM, and Splunk SOAR. You’ll also discover how to use and troubleshoot the Cisco Security Cloud App, Cisco Legacy Apps, and technology add-ons (TAs) for integrating Cisco security solutions with Splunk for enhancing user, cloud, and breach protections.
This training is worth 32 Continuing Education (CE) credits towards recertification.
Overview of Splunk Enterprise and Splunk Cloud
Splunk Enterprise and Splunk Cloud Components
Splunk Enterprise Data Ingestion
Splunk Search Programming Language
Splunk Dashboards and Reports
XDR, SIEM, and SOAR Platforms
Cisco XDR, Splunk SIEM, and Splunk SOAR
Cisco Security Cloud App
Cisco Secure Firewall Integration
Cisco XDR Integration
Cisco Secure Malware Analytics, Duo, Secure Network Analytics, Email Threat Defense, and Multicloud Defense Integrations
Cisco Security Legacy Apps and Technology Add-Ons
Cisco ISE Integration
Cisco NVM Integration
Cisco Security Solutions and Splunk Use Case
Cisco XDR and Splunk Use Case
Troubleshoot General Splunk Issues
Troubleshoot Cisco Security Cloud App
Troubleshoot Cisco Legacy Apps and Add-ons
Labs:
After completing this course, you should be able to:
Attendees should meet the following pre-requisites:
System and SOC Engineers needing to integrate Cisco Security Solutions with Splunk.
COURSE CONTENT: CCE Flows and Process Review Troubleshooting and Support Methodology PCCE Components PCCE Call Flow Review CCE Diagnostic Tools Diagnostic Framework Suite Run Analysis Manager Run Unified System…
COURSE CONTENT: Introducing Cisco ACI Fabric Infrastructure and Basic Concepts • What Is Cisco ACI? • Cisco ACI Topology and Hardware • Cisco ACI Object Model • Faults, Event…
COURSE CONTENT: Understanding Risk Management and SOC Operations Understanding Analytical Processes and Playbooks Investigating Packet Captures, Logs, and Traffic Analysis Investigating Endpoint and Appliance Logs Understanding Cloud Service Model…
We use cookies to improve your experience, including essential cookies required for the website to function. By continuing, you agree to our use of cookies. Learn more.