Kurs-ID: TDIBM_BQ205G
Kurs IBM QRadar SIEM Advanced Topics
QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses.
This 2-day instructor-led course walks you through various advanced topics about QRadar such as custom log sources, reference data collections and custom rules, X-Force data and the Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The course also discusses integration with IBM SOAR. Hands-on exercises reinforce the skills learned.
The lab environment for this course uses the IBM QRadar SIEM 7.5 platform.
Seminarinhalte
- Unit 1: Custom log sources
- Unit 2: Reference data collections and custom rules
- Unit 3: IBM X-Force Threat Intelligence in QRadar
- Unit 4: User Behavior Analytics and Advisor with Watson
- Unit 5: Tuning
- Unit 6: Custom action scripts
- Unit 7: IBM SOAR integration
Kursthemen
Das Training IBM QRadar SIEM Advanced Topics ist folgendem Thema zugeordnet:
Zielgruppe
This course is designed for security administrators and security analysts.
Voraussetzungen
- IT infrastructure
- IT security fundamentals
- Linux
- Windows
- TCP/IP networking
- Syslog
- Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)
Dauer und Zeiten
2 Kurstage
Termine
Kurspreis für offene Schulungen
1600,00 € zzgl. 19% MwSt. (1904,00 € inkl. 19% MwSt.)