Webové stránky používají k poskytování služeb, personalizaci reklam a analýze návštěvnosti soubory cookie. Informace, jak tyto stránky používáte, jsou sdíleny se společností Google. Používáním souhlasíte s použitím souborů cookie. Více informací.

Rozumím

Kód školení: SPLUNKAPI

Advanced Phantom Implementation

This 13.5 hour course is intended for experienced Phantom consultants who will be responsible for complex Phantom solution development, and will prepare the attendee to integrate Phantom with Splunk as well as develop playbooks requiring custom coding and REST API usage.
Potential attendees have received a passing grade in all prerequisite courses, and should ensure they can devote all of their attention to the class, as the course work is very challenging. Students will develop a custom solution with Phantom, Splunk and custom Python code. The labs provide requirements for the solution; the student must plan and execute the development. This will require thoughtful focus, experimentation and problem-solving skills.

Obsah školení

Module 1 – Implementing Splunk and Phantom
Review of Phantom UI and concepts
Describe interactions between Splunk and Phantom
Identify key concepts and data flows
Pre-requisites for integration

Module 2 – Configuring External Splunk Search
Describe the benefits of externalizing search to Splunk
Configure the Phantom instance for externalization
Configure the Splunk instance for externalization
Use the Splunk app for Phantom Reporting

Module 3 – Sending Splunk Events to Phantom
Configure the Phantom Add-on for Splunk
Map CIM fields to CEF
Send Enterprise Security notables to Phantom
Automatically trigger Phantom playbooks for Splunk notables

Module 4 – Accessing Splunk from Phantom
Install and configure the Phantom App for Splunk
Ingest Splunk events into Phantom
Use Splunk search from playbooks
Update Splunk notable events

Module 5 – Custom Coding in Playbooks
Phantom coding best practices
Writing, using and managing custom functions
Using the Phantom API in custom code
Store and retrieve persistent data

Module 6 – Using Phantom REST
Use Django queries to search for data in Phantom
Use REST from other systems to access Phantom data
Use the HTTP app to execute REST from playbooks

Předpokládané znalosti

Attendees for this class must ensure that they meet all course pre-requisites. This is a challenging, advanced class that draws on technical knowledge from many areas in Splunk and Phantom, and the demanding labs and course schedule leave little time to learn the basics.


Classes:

Experience with Python programming
Adminstering Splunk Phantom
Developing Splunk Phantom Playbooks
Enterprise Splunk Data Administration
Enterprise Splunk System Administration
Either Using or Administering Splunk Enterprise Security

Cena školení

36.900,- Kč bez DPH
44.649,- Kč s DPH

Termíny školení

Momentálně nejsou vypsané žádné termíny kurzu. Napište nám o termín.

Virtuální kurz

Datum Jazyk kurzu Délka kurzu
11. října 2021 Angličtina 13,5h Registrovat
13. října 2021 Angličtina 13,5h Registrovat
29. listopadu 2021 Angličtina 13,5h Registrovat
1. prosince 2021 Angličtina 13,5h Registrovat
10. ledna 2022 Angličtina 13,5h Registrovat
12. ledna 2022 Angličtina 13,5h Registrovat

Alternativní termín

Nevyhovuje vám žádný z navrhovaných termínů? Napište nám o vypsání alternativního termínu.

Kontaktujte nás