Professional skills
Elastic Security Analyst Workshop
Guided study of Elastic Security detection engine, alert triage, Timeline investigation, Attack Discovery, and AI Assistant modules.
THE BIG PICTURE
About this course
Elastic publishes a broad set of free, self-paced Elastic Security modules covering the detection engine, alerts and cases, Timeline investigation, Attack Discovery, AI Assistant, and ES|QL for security analysts. This guided session works through those modules with discussion time and practical triage exercises. Contact MindClick for the delivery format, teaching language, instructor profile, duration, dates, and a written fee proposal. Elastic, Elasticsearch, and Kibana are trademarks of Elasticsearch B.V. This listing describes training and study support on those products. It is not an official Elastic course, an Elastic certification, or a claim of authorized Elastic training-partner status. Certification exams are purchased and administered by Elastic.
What you’ll learn
- Apply the "Getting started: What is Elastic?" module to a task in your own environment.
- Apply the "Advanced ES|QL operations for security analysts" module to a task in your own environment.
- Apply the "Getting Started: Elastic Security" module to a task in your own environment.
- Apply the "Automating security operations with Elastic Workflows" module to a task in your own environment.
- Apply the "Intro to Elastic Security" module to a task in your own environment.
- Apply the "Elastic AI SOC Engine: EASE into Elastic Security" module to a task in your own environment.
A CLEAR PATH FORWARD
Recommended learning plan
Work through the free Elastic modules with a trainer, then apply each one to a task in your own environment.
- Learning route
- 5 recommended days
- Practical work
- 5 guided activities
- Finish with
- A practical review
Take a look at each day. Open a section to see the topics and practical work.
Day 1Getting started: What is Elastic? and Elastic AI SOC Engine: EASE into Elastic Security
What we’ll cover
- Getting started: What is Elastic?
- Elastic AI SOC Engine: EASE into Elastic Security
- Focus and investigate
- Advanced investigations with Timelines
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 2Advanced ES|QL operations for security analysts and Explore: Hosts, Network, and Users in Elastic Security
What we’ll cover
- Advanced ES|QL operations for security analysts
- Explore: Hosts, Network, and Users in Elastic Security
- Attack Discovery
- Machine learning for anomaly detection
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 3Getting Started: Elastic Security and Detection engine basics
What we’ll cover
- Getting Started: Elastic Security
- Detection engine basics
- AI Assistant for Security
- Actions and escalate
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 4Automating security operations with Elastic Workflows and Detection engine advanced
What we’ll cover
- Automating security operations with Elastic Workflows
- Detection engine advanced
- Visualizing data with Elastic for security analysts
- Security alert triage
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Day 5Intro to Elastic Security and Alerts and cases
What we’ll cover
- Intro to Elastic Security
- Alerts and cases
- ES|QL for security analysts
Put it into practice
Work through a guided exercise on this topic, explain your reasoning, and compare your approach with the group.
You’ll take away
A worked example with notes you can reuse at work.
Bring it all together
Review your worked examples with the trainer and agree the next steps for your own role.
Before you choose your learning route
Elastic, Elasticsearch, and Kibana are trademarks of Elasticsearch B.V. This listing describes training and study support on those products. It is not an official Elastic course, an Elastic certification, or a claim of authorized Elastic training-partner status. Certification exams are purchased and administered by Elastic.
Pricing
| Delivery format | Price per learner |
|---|---|
| Live online | $2,350 USD |
| Classroom | $4,500 USD |
Pricing for India is confirmed separately by an advisor and is not listed here. Singapore and Dubai are the priority classroom markets.
A listed price is not a quotation. Confirm the current fee, taxes, exam inclusion, study materials and any group rate in writing before enrolling.
Prerequisites
- No prior Elastic experience is required. Bring a laptop and an Elastic Cloud trial or test cluster.
Who is this course for?
- SOC analysts triaging and escalating Elastic Security alerts.
- Detection engineers tuning the detection engine and rules.
- Threat hunters using Timeline, Attack Discovery, and ES|QL.
Confirmed batch starts
Dates confirmed by MindClick. These are start dates, not full course timetables. Session hours, duration, fees, instructors, language, seats and classroom venues are not yet specified.
Choose your country & month Enrollment & payment
Starts 2026-10-24
Classroom · Dubai, United Arab Emirates · weekend start
Local date · Asia/Dubai
Venue to be confirmedStarts 2026-10-24
Classroom · Vienna, Austria · weekend start
Local date · Europe/Vienna
Venue to be confirmedStarts 2026-10-24
Classroom · Sydney, Australia · weekend start
Local date · Australia/Sydney
Venue to be confirmedStarts 2026-10-24
Classroom · Brussels, Belgium · weekend start
Local date · Europe/Brussels
Venue to be confirmedStarts 2026-10-24
Classroom · Manama, Bahrain · weekend start
Local date · Asia/Bahrain
Venue to be confirmedStarts 2026-10-24
Classroom · São Paulo, Brazil · weekend start
Local date · America/Sao_Paulo
Venue to be confirmedFrequently asked questions
Are the Elastic modules themselves free?
Yes. Elastic publishes these self-paced modules at no cost on elastic.co/training. MindClick charges only for the guided session: a trainer, structured agenda, discussion, and exercises mapped to your environment.
Is this an official Elastic course?
No. This is MindClick guided training built around Elastic free learning modules. It is not an official Elastic course and MindClick does not claim Elastic training-partner status.
Can this be delivered for a team?
Yes. Share your objectives, team size, preferred format, and dates, and MindClick will propose a suitable agenda and a written fee proposal.
What does this course cost?
Outside India this 5-day course is listed at USD 4,500 for classroom delivery and USD 2,350 for live online delivery, per learner. Pricing for India is confirmed separately by an advisor and is not listed here. Confirm taxes, exam fees, study materials and group rates in writing before enrolling; a listed price is not a quotation.
Where is classroom training delivered?
Singapore and Dubai are the priority classroom markets for this catalog. Classroom delivery is also available in the other listed countries, and live online delivery is available everywhere. Venues are confirmed per booking; a listed city is a training market, not an owned campus.
KEEP EXPLORING
More ways to move forward.
Related training from the course catalog.
Elasticsearch Engineer Training
Build, search, scale, and operate Elasticsearch clusters, then prepare for the Elastic Certified Engineer exam.
Data Analysis with Kibana
Analyze Elasticsearch data in Kibana, from aggregation charts to geo maps, machine learning results, and alerting.
Elastic Observability Engineer Training
Collect logs, metrics, uptime, and APM data into Elasticsearch, then analyze and act on it in Kibana.
Elastic Security for SIEM
Use Elastic Security for SIEM to triage alerts, investigate events in Timeline, and run a threat hunting capstone.