IBM QRadar SIEM Advanced Topics
IBM Training for IBM QRadar SIEM Advanced Topics
Skill Level: Advanced
Modality: CR - Classroom based Training or ILO - Instructor Led Online Class
Duration: 2 Day/s
Starting Price: $ - Contact
Overview:
Can you use QRadar SIEM to correlate various events and flow and trigger alerts of suspicious events? Learn to process uncommon QRadar events, work with reference data, custom rules and actions.
QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses. This 2-day instructor-led course walks you through various advanced topics about QRadar such as custom log sources, reference data collections and custom rules, X-Force data and the Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The course also discusses integration with IBM SOAR. Hands-on exercises reinforce the skills learned. The lab environment for this course uses the IBM QRadar SIEM 7.5 platform.
Request a Quote
Target Audience:
This course is designed for security administrators and security analysts.
Prerequisites: Students should be knowledgeable about the following topics:. IT infrastructure. IT security fundamentals. Linux. Windows. TCP/IP networking. Syslog. Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)
Topic: Unit 1: Custom log sourcesUnit 2: Reference data collections and custom rulesUnit 3: IBM X-Force Threat Intelligence in QRadarUnit 4: User Behavior Analytics and Advisor with WatsonUnit 5: TuningUnit 6: Custom action scriptsUnit 7: IBM SOAR integration
IBM Training
Objective: Learn how to create custom log sources. Discover how to work with reference data collections and custom rules. Use X-Force data and Threat Intelligence app. Use the Use Case Manager app. Learn how to use UBA and QRadar Advisor. Discover Tuning. Explore Custom action scripts. Discuss Integration with IBM SOAR
Category: Security
Product Name:
IBM Security QRadar SIEM
Badge and Certification Info:
Badge Title:
Badge ID: NONE
Brand: Threat Management
IBM Training is available now.
Cyber Retaliator Solutions (CRS) is a Cyber Security Value Added Channel Distributor, Authorized IBM Training Delivery Partner, Red Hat and SUSE Training Partner, CompTIA Delivery Partner operating throughout the Globe. Our Head Office is in Centurion South Africa, with IBM Training Centers in Centurion, Midrand, Sandton, Cape Town, California CA, Florida FL, New York NY, Washington DC, Georgia GA, Texas TX.
CRS is the Top Global Training Provider for some of the world's biggest brands.
Authorized Training delivered to you by the global leader in IBM Training.
Select courses in:
IBM Cloud
DataPower
IBM Automation
IBM Rational
Watson
IBM Systems
Cognos
IBM Storage
Mainframe
IBM Security
System Z
IBM Industry