Advanced SOAR Implementation
This 13.5 hour course is intended for experienced SOAR consultants who will be responsible for complex SOAR solution development, and will prepare the attendee to integrate SOAR with Splunk as well as develop playbooks requiring custom coding and REST API usage.
Potential attendees have received a passing grade in all prerequisite courses, and must ensure they can devote all of their attention to the class, as the course work is very challenging. Students will develop a custom solution with SOAR, Splunk and custom Python code. The labs provide requirements for the solution; the student must plan and execute the development. This will require thoughtful focus, experimentation and problem-solving skills.
Osallistumismuoto
Remote
Kesto
2 päivää
Hinta
1500 €
- Using external search in SOAR
- Sending events from Splunk to SOAR
- Updating Splunk events from SOAR
- Running SOAR reports on Splunk
- Executing SOAR playbooks from Splunk
- Searching Splunk from SOAR playbooks
- Writing custom code in SOAR playbooks
- Using the SOAR REST API in Phantom playbooks
Attendees for this class must ensure that they meet all course pre-requisites. This is a challenging, advanced class that draws on technical knowledge from many areas in Splunk and SOAR, and the demanding labs and course schedule leave little time to learn the basics.
Classes:
Either
UsingorAdministering Splunk Enterprise SecurityModule 1 - Implementing Splunk and SOAR
- Review of SOAR UI and concepts
- Describe interactions between Splunk and SOAR
- Identify key concepts and data flows
- Pre-requisites for integration
Module 2 - Configuring External Splunk Search
Module 3 - Sending Splunk Events to SOAR
Module 4 - Accessing Splunk from SOAR
Module 5 - Custom Coding in Playbooks
Module 6 - Using SOAR REST
Hinta 1500 € +alv
Pidätämme oikeudet mahdollisiin muutoksiin ohjelmassa, kouluttajissa ja toteutusmuodossa.
Katso usein kysytyt kysymykset täältä.