Note / Price varies according to the selected city
Price per participant, per week $4500 - $6500 (depends on the city)
Register 3 participants on the same course and pay for 2 only
A SOC analyst who has to triage three hundred alerts a shift will eventually start clicking through them on autopilot – and that is exactly the moment a real intrusion slips past unnoticed. Alert fatigue, not a lack of tools, is one of the most common reasons security monitoring fails in practice. The Security Operations Centre and SIEM Monitoring Training Course tackles that problem directly, building the judgement analysts need to separate a genuine threat from routine noise before it becomes a missed incident.
From there the programme works through how a SOC actually operates day to day: how SIEM platforms collect and correlate logs from across the enterprise, how detection use cases get designed and tuned, how Splunk is used operationally rather than just described in theory, and how an event moves from a triaged alert to a documented investigation to a properly escalated incident. It closes with how organisations measure and continuously improve SOC performance, so monitoring capability keeps pace with a changing threat environment.
By the end of this course, participants will be able to:
Target Audience
Module 1: Why Alert Fatigue Is a SOC’s Biggest Enemy
Module 2: What a Security Operations Centre Actually Does
Module 3: Inside SIEM Architecture – From Raw Logs to Insight
Module 4: Correlating Events to See the Real Picture
Module 5: Detecting Threats Across Endpoints, Network and Cloud
Module 6: Splunk in Practice – Searching, Dashboards and Investigation
Module 7: Designing Use Cases That Actually Catch Something
Module 8: From Alert to Investigation – Analysing Security Incidents
Module 9: Escalating the Right Incidents to the Right People
Module 10: Measuring, Governing and Improving SOC Performance
Security Operations Centre and SIEM Monitoring Training Course (Online / Remote)
2026-11-09
2027-02-08
2027-05-10
2027-08-09