Skip to main content
CYB-0050ProfessionalCurrent Intake
TH-SIEM

Threat Hunting with Splunk or ELK

3-Day Instructor-Led Programme

Learn proactive threat hunting techniques using SIEM platforms through mentor-led sessions and practical investigation scenarios. This programme focuses on building threat hypotheses, conducting hunts, and developing detections using SIEM tools.

Duration

3 Days

Price

$1,899

Threat Hunting with Splunk or ELK
Duration
3 Days
Complete in 3 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Traditional security monitoring relies heavily on alerts, but sophisticated threats often evade automated detection. Threat hunting enables security teams to proactively search for hidden threats by analysing patterns, anomalies, and behavioural indicators across systems and networks.

This mentor-led programme introduces practical threat hunting methodologies used by modern security operations teams. Learners explore how to develop hypotheses, analyse log data, and conduct structured hunts using SIEM platforms such as Splunk and the Elastic Stack.

Through practical scenarios and guided exercises, participants perform threat investigations, create detection logic, and develop repeatable hunting workflows. By the end of the programme, learners understand how to move from hypotheses to validated detections that strengthen organisational security monitoring.

Hands-On Learning

Practical exercises conducting threat hunts and analysing SIEM data using Splunk or ELK environments.

Mentor-Led Sessions

Experienced cyber security mentors guide learners through structured threat hunting investigations.

Career-Ready Skills

Threat hunting and detection engineering skills used by SOC analysts and cyber threat hunters.

Learning Outcomes

Understand modern threat hunting methodologies

Develop threat hunting hypotheses and investigation plans

Analyse security logs using SIEM platforms

Identify hidden threats and suspicious behaviour patterns

Convert hunting insights into detection rules

Document and communicate threat hunting results

Prerequisites

1

Basic understanding of networking and cyber security concepts.

2

Familiarity with security monitoring or SOC operations is recommended.

3

Prior experience with SIEM tools or log analysis is helpful.

Detailed Syllabus

Step-by-step learning journey from basics to professional practice

Topics Covered

  • Introduction to threat hunting concepts
  • Overview of SIEM platforms
  • Learning environment orientation

Skills You'll Gain

Master these in-demand skills through hands-on practice

Threat hunting methodologiesSIEM log analysis techniquesHypothesis-driven investigationDetection engineering basicsSecurity monitoring optimisationThreat investigation documentation

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Threat HunterSOC Analyst – Level 2Security AnalystDetection EngineerIncident Response Analyst
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

3 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$1,899+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Threat Hunting with Splunk or ELK learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Awarding Organisation
Xcademia
Credential Awarded
Certificate of Completion

Important Information

Learners who successfully complete the programme receive a Threat Hunting with SIEM Certificate of Completion from Xcademia.

Credential

Certificate of Completion

On successful completion of Threat Hunting with Splunk or ELK, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.

Frequently Asked Questions

Everything you need to know about this course

Threat hunting is a proactive cyber security practice where analysts search for hidden threats within systems and networks.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options