I am writing a short report on std. features of the ES I can use with little effort. We have Splunk Ent. 8.0 & have installed ES on it.
There are A LOT of things you can do with it. But for the very most common things, I would say look at the topics & objectives for ES in the Splunk Training & Certification course descriptions:
https://www.splunk.com/en_us/training/courses/using-splunk-enterprise-security.html
https://www.splunk.com/en_us/training/courses/administering-splunk-enterprise-security.html