From the course: Splunk for Security Analytics and Monitoring

Unlock the full course today

Join today to access over 24,900 courses taught by industry experts.

What's next?

What's next?

- [Instructor] Okay, so we finished our Splunk course. Splunk is a large product, it has a lot of moving parts that can work together depending on your deployment. So what should we do next? The next thing to consider is experimenting with the product in your environment. Now, I wouldn't recommend doing that in a production environment, have a sandbox testing environment that mimics what you would actually be doing in production. So make lists, review the potential sources of data on your network where you want to ingest that data into Splunk. Think about the overall need, if you work backwards and say, what is my need? Then you'll be able to very quickly identify how that need will be met. Maybe you need to monitor performance metrics for a number of mission critical web applications, and you also want to be able to monitor for network intrusions, so find out where that would be done on your network because that will also…

Contents