Splunk Enterprise Security Certified Admin Exam Study Guide

Splunk-Enterprise-Security-Certified-Admin

Splunk Enterprise Security Certified Admin Preparation Details

The Splunk Enterprise Security Certified Admin exam validates your ability to install, configure, and administer Splunk Enterprise Security for a SOC. This legacy certification covers dashboards, correlation searches, threat intelligence, and data onboarding across an ES deployment. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills.

Splunk Enterprise Security Certified Admin Materials

CourseraSIEM Splunk Hands-On Guide
UdemySplunk SIEM: Fundamentals to Advanced Analytics
WhizlabsSplunk Basics Training Course

1.0 ES Introduction 5%

Topics Covered

1.1 Overview of ES features and concepts

About Splunk Enterprise Security

Splunk Enterprise Security Features

Splunk Enterprise Security

Available dashboards in Splunk Enterprise Security

2.0 Monitoring and Investigation 10%

Topics Covered

2.1 Security posture

Security posture dashboard

Available dashboards in Splunk Enterprise Security

2.2 Incident review

Overview of Incident Review in Splunk Enterprise Security

Managing Incident Review in Splunk Enterprise Security

Take action on a notable on Incident Review in Splunk Enterprise Security

2.3 Notable events management

Investigate a notable on Incident Review in Splunk Enterprise Security

Managing Incident Review in Splunk Enterprise Security

Take action on a notable on Incident Review in Splunk Enterprise Security

2.4 Investigations

Investigations in Splunk Enterprise Security

Start investigations in Splunk Enterprise Security

Manage investigations in Splunk Enterprise Security

Using the workbench in an Enterprise Security investigation

3.0 Security Intelligence 5%

Topics Covered

3.1 Overview of security intel tools

Available dashboards in Splunk Enterprise Security

Configure threat intelligence sources in Splunk Enterprise Security

User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security

4.0 Forensics, Glass Tables, and Navigation Control 10%

Topics Covered

4.1 Explore forensics dashboards

Available dashboards in Splunk Enterprise Security

Using Enterprise Security for security investigation and monitoring

4.2 Examine glass tables

Overview of the glass table editor in ITSI

Tutorial: Build a glass table to monitor your infrastructure

4.3 Configure navigation and dashboard permissions

Create and manage views in Splunk Enterprise Security

Configure dashboard permissions

5.0 ES Deployment 10%

Topics Covered

5.1 Identify deployment topologies

Deployment considerations for Splunk Enterprise Security

Install Splunk Enterprise Security in a search head cluster environment

Install Splunk Enterprise Security on an on-prem search head

5.2 Examine the deployment checklist

Deployment considerations for Splunk Enterprise Security

Install Splunk Enterprise Security on an on-prem search head

Configure and deploy indexes for Splunk Enterprise Security

5.3 Understand indexing strategy for ES

Configure and deploy indexes for Splunk Enterprise Security

5.4 Understand ES Data Models

Overview of the Splunk Common Information Model

Splunk Common Information Model (CIM)

6.0 Installation and Configuration 15%

Topics Covered

6.1 Prepare a Splunk environment for installation

Install Splunk Enterprise Security on an on-prem search head

Deployment considerations for Splunk Enterprise Security

6.2 Download and install ES on a search head

Install Splunk Enterprise Security

Install Splunk Enterprise Security on an on-prem search head

Install Splunk Enterprise Security in a search head cluster environment

6.3 Understand ES Splunk user accounts and roles

Configure users and roles in Splunk Enterprise Security

Configure and administer Splunk Enterprise Security

6.4 Post-install configuration tasks

Install Splunk Enterprise Security

Upgrade Splunk Enterprise Security

Configure and deploy indexes for Splunk Enterprise Security

7.0 Validating ES Data 10%

Topics Covered

7.1 Plan ES inputs

Configure and deploy indexes for Splunk Enterprise Security

Overview of the Splunk Common Information Model

7.2 Configure technology add-ons

About the Splunk Add-on Builder

Use the Splunk Add-on Builder

Splunk Common Information Model (CIM)

8.0 Custom Add-ons 5%

Topics Covered

8.1 Design a new add-on for custom data

Design your add-on

About the Splunk Add-on Builder

Create an add-on

8.2 Use the Add-on Builder to build a new add-on

Use the Splunk Add-on Builder

Install the Add-on Builder

Use the add-on

9.0 Tuning Correlation Searches 10%

Topics Covered

9.1 Configure correlation search scheduling and sensitivity

Configure correlation searches in Splunk Enterprise Security

Part 4: Schedule the correlation search

9.2 Tune ES correlation searches

Correlation search overview for Splunk Enterprise Security

Configure correlation searches in Splunk Enterprise Security

10.0 Creating Correlation Searches 10%

Topics Covered

10.1 Create a custom correlation search

Correlation search overview for Splunk Enterprise Security

Configure correlation searches in Splunk Enterprise Security

10.2 Configuring adaptive responses

Configure adaptive response actions for detections in Splunk Enterprise Security

Set up Adaptive Response actions in Splunk Enterprise Security

Configure adaptive response action relays in Splunk Enterprise Security

10.3 Search export/import

Export content from Splunk Enterprise Security as an app

Managing content in Splunk Enterprise Security

11.0 Lookups and Identity Management 5%

Topics Covered

11.1 Identify ES-specific lookups

Create and manage lookups in Splunk Enterprise Security

Manage internal lookups in Splunk Enterprise Security

11.2 Understand and configure lookup lists

Manage identity lookup configuration policies in Splunk Enterprise Security

Create and manage lookups in Splunk Enterprise Security

12.0 Threat Intelligence Framework 5%

Topics Covered

12.1 Understand and configure threat intelligence

Configure threat intelligence sources in Splunk Enterprise Security

Using threat intelligence in Splunk Enterprise Security

12.2 Configure user activity analysis

User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security

Behavior-based detections for UEBA in Splunk Enterprise Security

Wrapping Up Splunk Enterprise Security Certified Admin

This guide walked through every domain of the Splunk Enterprise Security Certified Admin exam, from ES installation and data onboarding to correlation searches and threat intelligence. Reviewing each objective alongside the linked Splunk documentation will help you build hands-on confidence with the ES app before exam day. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Enterprise Security Certified Admin Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Enterprise Security Certified Admin Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *