Cisco træning

Insoft Services er en af de få uddannelsesudbydere i EMEAR, der tilbyder hele spektret af Cisco-certificering og specialiseret teknologiuddannelse.

Lær hvordan

Cisco-certificeringer

Oplev en blandet læringsmetode, der kombinerer det bedste fra instruktørstyret træning og e-læring i eget tempo for at hjælpe dig med at forberede dig til din certificeringseksamen.

Lær hvordan

Cisco Learning Credits

Cisco Learning Credits (CLCs) er forudbetalte træningskuponer, der indløses direkte med Cisco, og som gør det nemmere at planlægge din succes, når du køber Cisco-produkter og -tjenester.

Lær hvordan

Cisco Efteruddannelse

Cisco Continuing Education Program tilbyder alle aktive certificeringsindehavere fleksible muligheder for at gencertificere ved at gennemføre en række kvalificerede træningselementer.

Lær hvordan

Cisco Digital Learning

Certificerede medarbejdere er VÆRDSATTE aktiver. Udforsk Ciscos officielle digitale læringsbibliotek for at uddanne dig selv gennem optagede sessioner.

Lær hvordan

Cisco Business Enablement

Cisco Business Enablement Partner Program fokuserer på at skærpe Cisco Channel Partners og kunders forretningsmæssige færdigheder.

Lær hvordan

Cisco kursuskatalog

Lær hvordan

Fortinet-certificeringer

Fortinet Network Security Expert (NSE) -programmet er et otte-niveau uddannelses- og certificeringsprogram for at undervise ingeniører i deres netværkssikkerhed for Fortinet FW-færdigheder og erfaring.

Lær hvordan

Fortinet træning

Insoft er anerkendt som Autoriseret Fortinet Training Center på udvalgte steder på tværs af EMEA.

Tekniske kurser

Fortinet kursuskatalog

Udforsk hele Fortinet-træningskataloget. Programmet omfatter en bred vifte af selvstændige og instruktørledede kurser.

Lær hvordan

ATC-status

Tjek vores ATC-status på tværs af udvalgte lande i Europa.

Lær hvordan

Fortinet Professionelle Services

Globalt anerkendte team af certificerede eksperter hjælper dig med at gøre en mere jævn overgang med vores foruddefinerede konsulent-, installations- og migreringspakker til en lang række Fortinet-produkter.

Lær hvordan

Microsoft træning

Insoft Services tilbyder Microsoft-undervisning i EMEAR. Vi tilbyder Microsoft tekniske kurser og certificeringskurser, der ledes af instruktører i verdensklasse.

Tekniske kurser

Extreme træning

Find all the Extreme Networks online and instructor led class room based calendar here.

Tekniske kurser

Tekniske certificeringer

Vi leverer omfattende læseplan for tekniske kompetencefærdigheder på certificeringspræstationen.

Lær hvordan

Extreme kursuskatalog

Lær hvordan

ATP-akkreditering

Som autoriseret uddannelsespartner (ATP) sikrer Insoft Services, at du får de højeste uddannelsesstandarder, der findes.

Lær hvordan

Løsninger og tjenester

Vi leverer innovativ og avanceret support til design, implementering og optimering af IT-løsninger. Vores kundebase omfatter nogle af de største Telcos globalt.

Lær hvordan

Globalt anerkendte team af certificerede eksperter hjælper dig med at gøre en mere jævn overgang med vores foruddefinerede konsulent-, installations- og migreringspakker til en lang række Fortinet-produkter.

Om os

Insoft tilbyder autoriseret uddannelses- og konsulentbistand til udvalgte IP-leverandører. Få mere at vide om, hvordan vi revolutionerer branchen.

Lær hvordan
  • +45 32 70 99 90
  • ESM 201 - Advanced Enterprise Security Manager SIEM Administration

    Duration
    4 Dage
    Delivery
    (Online Og På stedet)
    Price
    Pris på forespørgsel

    Enterprise Security Manager—the heart of our security information and event management (SIEM) solution—provides near real-time visibility into the activity on all your systems, networks, databases, and applications. This enables you to detect, correlate, and remedy threats in minutes across your entire IT infrastructure.

     

    This course prepares Enterprise Security Manager engineers and analysts to understand, communicate, and use the features provided by Enterprise Security Manager. Through demonstration, explanation, and hands-on lab exercises, you will learn how to utilize the Enterprise Security Manager by using recommended best practices and methodologies.

    Contextual Configurations

    Utilize Asset Manager and how to manage assets and asset groups. Define and configure data enrichment using the Data Enrichment Wizard and Integrate vulnerability assessment (VA) tool with ESM.

     

    Advanced Data Sources

    Configure Auto Learn to listen to incoming events after installing and configuring the SIEM Collector Agent.

     

    Alarms, Actions, and Notifications

    Describe alarms, Build and edit templates, use remote commands, create report queries, Configure notifications

     

    Data Streaming Bus

    Display adding Data Streaming Databus (DSB) and configuring Data Routing, Data Sharing, and creating Message Forwarding Rules.

     

    Advanced Syslog Parser

    Understand Regex and available resources. Discussion on handling of unknown events and creating custom parsing rules.

     

    Aggregation

    Customize event and flow aggregation fields on a per- signature basis, and define the advantages and nuances associated with event and flow aggregation.

     

    Current Threat and Vulnerability Use Cases

    Research current threats and vulnerabilities. Create use cases from current threats and vulnerabilities.

     

    ESM and Tuning Best Practice

    Learn Event Tuning methodology. Configure events filtering on ERC and Identify key strategies for tuning correlation rules. Learn best practice to enhance ESM performance.

     

    Advanced Correlation

    Utilize advanced rule correlation options and deviation-based rule correlation and risk correlation.

     

    Analyst Tasks

    Make tuning recommendations according to your analysis while Identifying events for immediate action, delayed action and no action (triage).

     

    Use Case Overview

    Define use cases and follow a process to develop well defined use cases.

     

    Management Event Use Cases

    Create use cases from management directives.

     

    Organizational Use Case Policies

    Create use cases from organizational policies

     

    Compliance Use Cases

    Create use cases from regulations to validate compliance.

     

    Incident Identification Use Cases

    Create use cases to quickly identify previously remediated incidents.

    Day 1

    • Welcome
    • Contextual Configurations
    • Advanced Data Source Options
    • Alarms, Actions, Notifications, and Reports

     

    Day 2

    • Data Streaming Bus
    • Advanced Syslog Parser
    • ESM Tuning and Best Practice
    • Performance Troubleshooting

     

    Day 3

    • Advanced Correlation
    • Analyst Tasks
    • Use Case Overview
    • Management Directives Use Cases

     

    Day 4

    • Organizational Policies Use Cases
    •  
    • Compliance Use Cases
    • Current Threats and Vulnerabilities Use Cases
    • Incident Identification Use cases

    This course is aimed at Enterprise Security Manager users, responsible for monitoring activity on systems, networks, databases, applications, and for configuration and management of the Enterprise Security Manager solution. Attendees should have a working knowledge of networking and system administration concepts, a good understanding of computer security concepts, and a general understanding of networking and application software.

    It is recommended that students have a working knowledge of networking and system administration concepts.

    Enterprise Security Manager—the heart of our security information and event management (SIEM) solution—provides near real-time visibility into the activity on all your systems, networks, databases, and applications. This enables you to detect, correlate, and remedy threats in minutes across your entire IT infrastructure.

     

    This course prepares Enterprise Security Manager engineers and analysts to understand, communicate, and use the features provided by Enterprise Security Manager. Through demonstration, explanation, and hands-on lab exercises, you will learn how to utilize the Enterprise Security Manager by using recommended best practices and methodologies.

    Contextual Configurations

    Utilize Asset Manager and how to manage assets and asset groups. Define and configure data enrichment using the Data Enrichment Wizard and Integrate vulnerability assessment (VA) tool with ESM.

     

    Advanced Data Sources

    Configure Auto Learn to listen to incoming events after installing and configuring the SIEM Collector Agent.

     

    Alarms, Actions, and Notifications

    Describe alarms, Build and edit templates, use remote commands, create report queries, Configure notifications

     

    Data Streaming Bus

    Display adding Data Streaming Databus (DSB) and configuring Data Routing, Data Sharing, and creating Message Forwarding Rules.

     

    Advanced Syslog Parser

    Understand Regex and available resources. Discussion on handling of unknown events and creating custom parsing rules.

     

    Aggregation

    Customize event and flow aggregation fields on a per- signature basis, and define the advantages and nuances associated with event and flow aggregation.

     

    Current Threat and Vulnerability Use Cases

    Research current threats and vulnerabilities. Create use cases from current threats and vulnerabilities.

     

    ESM and Tuning Best Practice

    Learn Event Tuning methodology. Configure events filtering on ERC and Identify key strategies for tuning correlation rules. Learn best practice to enhance ESM performance.

     

    Advanced Correlation

    Utilize advanced rule correlation options and deviation-based rule correlation and risk correlation.

     

    Analyst Tasks

    Make tuning recommendations according to your analysis while Identifying events for immediate action, delayed action and no action (triage).

     

    Use Case Overview

    Define use cases and follow a process to develop well defined use cases.

     

    Management Event Use Cases

    Create use cases from management directives.

     

    Organizational Use Case Policies

    Create use cases from organizational policies

     

    Compliance Use Cases

    Create use cases from regulations to validate compliance.

     

    Incident Identification Use Cases

    Create use cases to quickly identify previously remediated incidents.

    Day 1

    • Welcome
    • Contextual Configurations
    • Advanced Data Source Options
    • Alarms, Actions, Notifications, and Reports

     

    Day 2

    • Data Streaming Bus
    • Advanced Syslog Parser
    • ESM Tuning and Best Practice
    • Performance Troubleshooting

     

    Day 3

    • Advanced Correlation
    • Analyst Tasks
    • Use Case Overview
    • Management Directives Use Cases

     

    Day 4

    • Organizational Policies Use Cases
    •  
    • Compliance Use Cases
    • Current Threats and Vulnerabilities Use Cases
    • Incident Identification Use cases

    This course is aimed at Enterprise Security Manager users, responsible for monitoring activity on systems, networks, databases, applications, and for configuration and management of the Enterprise Security Manager solution. Attendees should have a working knowledge of networking and system administration concepts, a good understanding of computer security concepts, and a general understanding of networking and application software.

    It is recommended that students have a working knowledge of networking and system administration concepts.

      Kommende datoer
      Dato på anmodning

    Follow Up Courses

    Filtrer
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 2 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 5 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now
    • 4 Dage
      Dato på anmodning
      Price on Request
      Book Now

    Know someone who´d be interested in this course?
    Let them know...

    Use the hashtag #InsoftLearning to talk about this course and find students like you on social media.