IT Infrastructure & Networks Category Banner Image

Enhancing Cisco Security Solutions with Data Analytics (ECSS)

  • Length 5 days
  • Version 1.0
Course overview
View dates &
book now
Register interest

Why study this course

The Enhancing Cisco Security Solutions with Data Analytics (ECSS) course covers intermediate-level knowledge of Splunk, including its fundamentals, key components, and architecture so you can detect, investigate, and respond to security threats effectively. You’ll learn to utilise various Splunk components, including Cisco XDR, Splunk SIEM, and Splunk SOAR. You’ll also discover how to use and troubleshoot the Cisco Security Cloud App, Cisco Legacy Apps, and technology add-ons (TAs) for integrating Cisco security solutions with Splunk for enhancing user, cloud, and breach protections.

This training also earns you 32 Continuing Education (CE) credits toward recertification.

Digital courseware: Cisco provides students with electronic courseware for this course. Students who have a confirmed booking will be sent an email prior to the course start date, with a link to create an account via learningspace.cisco.com before they attend their first day of class. Please note that any electronic courseware or labs will not be available (visible) until the first day of the class.

Exam Vouchers: Cisco exam vouchers are not included in the course fees but can be purchased separately where applicable.

Please note: This course is due to be released by Cisco on July 31, 2025.

Request Course Information


What you’ll learn

After taking this course, you should be able to:

  • Explain the Splunk Enterprise/Cloud fundamentals

  • Explain the use of XDR, SIEM, SOAR as part of the modern SOC architecture to enhance the SOC’s ability to detect, investigate, and respond to security threats effectively

  • Implement Cisco Security Solutions to Splunk Integration using the Cisco Security Cloud App

  • Implement Cisco Security Solutions to Splunk Integration using Cisco Legacy Apps and TAs

  • Illustrate the value of integrating Cisco security solutions with Splunk using real-world use cases

  • Troubleshoot the Cisco Security Cloud App and the Cisco Apps and TAs


Cisco Partner logo

Cisco at Lumify Work

Lumify Work is the largest provider of authorised Cisco training in Australia, offering a wider range of Cisco courses, run more often than any of our competitors. Lumify Work has won awards such as ANZ Learning Partner of the Year (twice!) and APJC Top Quality Learning Partner of the Year.


Who is the course for?

  • System Engineers

  • SOC Engineers

  • Network Architects


Course subjects

  • Overview of Splunk Enterprise and Splunk Cloud

  • Splunk Enterprise and Splunk Cloud Components

  • Splunk Enterprise Data Ingestion

  • Splunk Search Programming Language

  • Splunk Dashboards and Reports

  • XDR, SIEM, and SOAR Platforms

  • Cisco XDR, Splunk SIEM, and Splunk SOAR

  • Cisco Security Cloud App

  • Cisco Secure Firewall Integration

  • Cisco XDR Integration

  • Cisco Secure Malware Analytics, Duo, Secure Network Analytics, Email Threat Defense, and Multicloud Defense Integrations

  • Cisco Security Legacy Apps and Technology Add-Ons

  • Cisco ISE Integration

  • Cisco NVM Integration

  • Cisco Security Solutions and Splunk Use Case

  • Cisco XDR and Splunk Use Case

  • Troubleshoot General Splunk Issues

  • Troubleshoot Cisco Security Cloud App

  • Troubleshoot Cisco Legacy Apps and Add-ons

Lab Outline

  • Explore Splunk Indexes

  • Explore Splunk Web and CLI

  • Verify and Test Data Ingestion

  • Malware Events Analysis Using Splunk Enterprise Simulation

  • Perform Search Queries

  • Create Dashboards and Reports

  • Explore Splunk SOAR

  • Explore Cisco XDR Incident Investigation

  • Cisco Secure Firewall Integration with Splunk

  • Cisco XDR to Splunk Enterprise Integration Simulation

  • Cisco Duo Integration Simulation

  • Cisco SMA Integration Simulation

  • Cisco SNA Integration Simulation

  • Explore the Cisco ISE Integration with Splunk Using the Legacy ISE App and TA

  • Explore the Cisco NVM Integration with Splunk Using the Legacy CESA App and TA

  • Investigate Ransomware Using Splunk Enterprise with the Various Cisco Security Apps

  • Troubleshoot Cisco Security Cloud App with Cisco Secure Firewall Integration

  • Troubleshooting Cisco ISE Integration with Splunk

  • Troubleshooting Cisco NVM Integration with Splunk


Prerequisites

There are no prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:

These skills can be found in the following course:



Terms & Conditions

The supply of this course by Lumify Work is governed by the booking terms and conditions. Please read the terms and conditions carefully before enrolling in this course, as enrolment in the course is conditional on acceptance of these terms and conditions.


Request Course Information

Awaiting course schedule

If you would like to receive a notification when this course becomes available, enter your details below.

Personalise your schedule with Lumify USchedule

Interested in a course that we have not yet scheduled? Get in touch, and ask for your preferred date and time. We can work together to make it happen.