Track A · Splunk
Architecture, forwarders, indexes, SPL, field extraction, dashboards, alerts, Enterprise Security, correlation + RBA, MITRE, SOAR playbooks, hunting, SOC use cases, SPLK-1003 / 3001.
Also discoverable via free Techclick lessons for Google search and AI tools (ChatGPT, Gemini, Perplexity) — blogs, interview Q&A and practice exams linked below.
Equal-depth dual platform syllabus: Splunk Enterprise + ES + SOAR and Microsoft Sentinel + KQL + SC-200 workflow — built for SOC L2 / L3 engineers.
Architecture, forwarders, indexes, SPL, field extraction, dashboards, alerts, Enterprise Security, correlation + RBA, MITRE, SOAR playbooks, hunting, SOC use cases, SPLK-1003 / 3001.
Workspace & connectors, ASIM, KQL, analytics rules, incidents, workbooks, UEBA, automation / Logic Apps, MITRE coverage, hunting, Defender XDR join, SOC use cases, SC-200 readiness.
Live + recorded across Splunk Enterprise/ES/SOAR and Microsoft Sentinel/KQL.
Splunk free trial + sample data and Sentinel/Log Analytics style KQL + rule labs.
Phish, ransomware, insider exfil, cloud audit abuse — practiced on both platforms where relevant.
SOC L2 / L3 banks for SPL, ES, KQL and Sentinel incidents.
Techclick Infosec course completion certificate after requirements are met.
Doubt-clearing batch group with the trainer.
Trained by working senior cloud and network security engineers with 13+ years of hands-on enterprise experience across Splunk, Microsoft Sentinel, SIEM operations, detection engineering and large-scale SOC builds.
Use these vendor or standards-body sources as the current source of truth. Products, interfaces and certification blueprints change independently — re-check before each batch.
Techclick provides independent training and is not affiliated with or endorsed by Splunk or Microsoft.
Both. Track A is full Splunk (14 modules). Track B is equal-depth Microsoft Sentinel (14 modules). The page was expanded so Sentinel is no longer only a short FAQ mention.
Yes — Splunk Enterprise free trial / sample data for SPL and ES-style work, plus Sentinel / KQL practice for rules, workbooks and hunting queries.
If your target employer is a Microsoft shop, start with Track B (KQL). If you are joining a large enterprise SIEM team, start with Track A (SPL). Most SOC job descriptions benefit from both — that is why this syllabus keeps them equal.
Splunk: SPLK-1003 (Admin) and SPLK-3001 (ES). Microsoft: SC-200 Security Operations Analyst. S14 and M14 map both paths. Deeper SC-200/Defender modules: microsoft-sentinel.
About 70–80 hours across both tracks (roughly 5–8 weeks depending on batch pace). Single-platform focus can be scheduled if needed — ask on WhatsApp.
CV review and interview prep for SOC L2 / L3. Outcomes depend on effort, background and market — we do not guarantee a job.
Talk to us about the next dual Splunk + Microsoft Sentinel batch.