← Back to Skills Library

Splunk Enterprise Security

Information Technology > Business intelligence and data analysis

Description

Splunk Enterprise Security (ES) is a powerful analytics-driven SIEM (Security Information and Event Management) solution that provides insight into machine data generated from security technologies such as network, endpoint, access, malware, vulnerability, and identity information. It helps in identifying, investigating, and responding to internal and external threats by providing real-time visibility across an organization's infrastructure. Users can create dashboards, visualizations, and alerts, perform risk analysis, and integrate external threat intelligence sources. Advanced users can design custom security solutions, optimize the system, and implement advanced threat detection strategies. Proficiency in Splunk ES requires understanding its architecture, mastering the Splunk Processing Language (SPL), and gaining hands-on experience with its various features.

Expected Behaviors

✎
LEVEL 1

Fundamental Awareness

At this level, individuals have a basic understanding of Splunk Enterprise Security and its core concepts. They are familiar with the concept of SIEM and know how to ingest data into Splunk. However, their skills are mostly theoretical and they may need guidance to perform tasks.

🌱
LEVEL 2

Novice

Novices can navigate the Splunk ES interface and use basic search commands. They understand correlation searches and notable events, and can create simple dashboards and visualizations. They are still learning and may make mistakes, but they can handle basic tasks with some confidence.

🌍
LEVEL 3

Intermediate

Intermediate users are proficient in using Splunk Processing Language (SPL) and can manage correlation searches. They understand the threat intelligence and risk analysis frameworks, and can configure glass tables. They can handle more complex tasks and solve problems with less supervision.

⭐
LEVEL 4

Advanced

Advanced users can configure and manage Splunk ES, create complex dashboards and visualizations, and integrate external threat intelligence sources. They understand advanced threat hunting techniques and can perform incident review and response. They can handle most tasks independently and provide guidance to less experienced users.

🏆
LEVEL 5

Expert

Experts have a deep understanding of Splunk architecture and deployment. They can optimize and troubleshoot Splunk ES, use advanced SPL commands and functions, and design custom security solutions. They are capable of detecting and responding to advanced threats. They can lead projects and mentor other team members.

Micro Skills

✎
LEVEL 1

Fundamental Awareness

Familiarity with the purpose and use of Splunk ES
Basic knowledge of the components of Splunk ES
Understanding of how Splunk ES fits into a security operations center (SOC)
Understanding of what SIEM is
Knowledge of the role of SIEM in cybersecurity
Awareness of the benefits of using a SIEM solution like Splunk ES
Understanding of how data is collected in Splunk
Familiarity with the types of data that can be ingested in Splunk
Basic knowledge of how to add data to Splunk
🌱
LEVEL 2

Novice

Identifying different parts of the interface
Understanding the function of each component
Learning the structure of a basic search command
Practicing basic search commands
Understanding the concept of correlation searches
Learning how to create a correlation search
Learning about dashboards
Creating a basic dashboard
Understanding the concept of notable events
Learning how to review and respond to notable events
🌍
LEVEL 3

Intermediate

Understanding of SPL command syntax
Ability to execute basic SPL commands
Knowledge of SPL query structure
Understanding of SPL syntax rules
Understanding of SPL functions
Ability to use SPL operators
Experience in creating SPL queries
Proficiency in modifying existing SPL queries
⭐
LEVEL 4

Advanced

Understanding of Splunk ES configuration files
Knowledge of user and role management in Splunk ES
Ability to manage data inputs and forwarders
Proficiency in configuring correlation searches and alerts
Ability to use advanced visualization components
Understanding of dashboard XML
Ability to create drilldowns in dashboards
Knowledge of dynamic form inputs for dashboards
Understanding of threat intelligence standards (STIX, TAXII)
Ability to configure threat intelligence downloads
Knowledge of threat intelligence matching in Splunk ES
Ability to manage threat intelligence artifacts
Knowledge of hypothesis-driven threat hunting
Ability to use advanced SPL for threat hunting
Understanding of common attack patterns and indicators of compromise
Ability to analyze and interpret hunt results
Understanding of the incident review process in Splunk ES
Ability to create and manage investigation workbooks
Knowledge of incident response workflows
Ability to use adaptive response actions for automated response
🏆
LEVEL 5

Expert

Knowledge of search head clustering
Understanding of indexer clustering
Proficiency in troubleshooting data ingestion issues
Ability to optimize search performance
Ability to use statistical and analytical functions
Ability to create and use macros
Understanding of how to customize dashboards and visualizations
Ability to create custom correlation searches
Understanding of advanced threat hunting techniques
Ability to design and implement incident response workflows

Skill Overview

  • Expert3 years experience
  • Micro-skills57
  • Roles requiring skill2

Sign up to prepare yourself or your team for a role that requires Splunk Enterprise Security.

LoginSign Up