After collecting all the logs and writing search quarries, How to do incident management and develop use-cases, and security playbooks.
you can start with these security essentials apps:
https://splunkbase.splunk.com/app/3435/
https://splunkbase.splunk.com/app/3593/
https://splunkbase.splunk.com/app/3693/
there are more in splunkbase
down the road maybe consider Splunk Enterprise Security