Participants joined us for a Splunk workshop designed to provide attendees with basic to advanced Splunk training.
Time |
Topics & Description |
9:30am - 11:30am |
Splunk 4 Rookies: Designed for Splunk beginners and anyone interested in getting hands-on experience working with machine data and gaining valuable IT Ops, Security, and Business Analytics insight from it. This workshop will provide an introduction to Splunk, along with hands-on experience creating a Splunk app and dashboard based on multiple use case scenarios. |
11:30am - 12:30pm |
Lunch: Splunk will provide lunch. |
12:30pm - 3:30pm |
Investigating with Splunk: This modular, hands-on workshop is designed to familiarize participants with how to investigate incidents using Splunk and Open Source. This workshop provides users a way to gain experience searching in Splunk to answer specific questions related to an investigation. |
Time |
Topics & Description |
9:30am - 10:30am |
Ask a Splunk Expert: Sign up for individual 30-minute sessions to ask any outstanding questions, concerns, and guidance on your existing Splunk deployment. During these personalized sessions, we will also review best practices or helpful training opportunities. |
10:30am - 3:00pm |
Advanced Threat Hunting: This workshop leverages Splunk Enterprise Security and introduces how models like the Lockheed Martin Kill Chain, MITRE ATT&CK, and Diamond Model can be used to contextualize their hunts. The workshop leverages the popular Boss of the SOC (BOTS) dataset in a multi-hunt format. Users will leave with a better understanding of how Splunk can be used to hunt for threats within their enterprise. This will be a working lunch with Splunk providing lunch. |