IBM QRadar SIEM Advanced Topics

2 Day Course
Code TPZL1_BQ204IBM

Overview

These courses are being delivered by an IBM Global Training Provider

QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses.

This 2-day course walks you through various advanced topics about QRadar such as custom log sources, reference data collections and custom rules, X-Force data and the Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The course also discusses integration with IBM SOAR. Hands-on exercises reinforce the skills learned.

The lab environment for this course uses the IBM QRadar SIEM 7.4 platform.

Objectives

Students should be knowledgeable about the following topics:

IT infrastructure
IT security fundamentals
Linux
Windows
TCP/IP networking
Syslog
Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)

Target Audience

This course is designed for security administrators and security analysts.

Training Partners

We work with the following best of breed training partners using our bulk buying power to bring you a wider range of dates, locations and prices.

Modules

Collapse all

Unit 1: (1 topic)

  • Custom log sources

Unit 2: (1 topic)

  • Reference data collections and custom rules

Unit 3: (1 topic)

  • IBM X-Force Threat Intelligence in QRadar

Unit 4: (1 topic)

  • User Behavior Analytics and Advisor with Watson

Unit 5: (1 topic)

  • Tuning

Unit 6: (1 topic)

  • Custom action scripts

Prerequisites

Students should be knowledgeable about the following topics:

IT infrastructure
IT security fundamentals
Linux
Windows
TCP/IP networking
Syslog
Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)

Course PDF

Print

Share this Course

Share

Recommend this Course

Sections