IBM QRadar SIEM Advanced Topics (BQ204G)

 

Course Overview

QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses.

This 2-day course walks you through various advanced topics about QRadar such as custom log sources, reference data collections and custom rules, X-Force data and the Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The course also discusses integration with IBM SOAR. Hands-on exercises reinforce the skills learned.

Who should attend

This course is designed for security administrators and security analysts.

Prerequisites

Students should be knowledgeable about the following topics:

  • IT infrastructure
  • IT security fundamentals
  • Linux
  • Windows
  • TCP/IP networking
  • Syslog
  • Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)

Course Objectives

  • Learn how to create custom log sources
  • Discover how to work with reference data collections and custom rules
  • Use X-Force data and Threat Intelligence app
  • Use the Use Case Manager app
  • Learn how to use UBA and QRadar Advisor
  • Discover Tuning
  • Explore Custom action scripts
  • Discuss Integration with IBM SOAR

Outline: IBM QRadar SIEM Advanced Topics (BQ204G)

  • Unit 1: Custom log sources
  • Unit 2: Reference data collections and custom rules
  • Unit 3: IBM X-Force Threat Intelligence in QRadar
  • Unit 4: User Behavior Analytics and Advisor with Watson
  • Unit 5: Tuning
  • Unit 6: Custom action scripts
  • Unit 7: IBM SOAR integration

Prices & Delivery methods

Online Training

Duration
2 days

Price
  • Online Training: CAD 1,640
  • Online Training: US$ 1,630
Classroom Training

Duration
2 days

Price
  • Canada: CAD 1,640

Click on town name or "Online Training" to book Schedule

This is an Instructor-Led Classroom course
Guaranteed date:   We will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.
*   This class is delivered by a partner.

Europe

Germany

Online Training Time zone: Europe/Berlin * Enroll
Online Training Time zone: Europe/Berlin * Enroll
Guaranteed to Run Online Training Time zone: Europe/Berlin * Enroll
Online Training Time zone: Europe/Berlin * Enroll
Online Training Time zone: Europe/Berlin * Enroll
Leinfelden-Echterdingen * Enroll
Online Training Time zone: Europe/Berlin * Enroll
Online Training Time zone: Europe/Berlin * Enroll
Online Training Time zone: Europe/Berlin * Enroll

France

Online Training Time zone: Europe/Paris * Enroll
Online Training Time zone: Europe/Paris * Enroll
Online Training Time zone: Europe/Paris * Enroll
Online Training Time zone: Europe/Paris * Enroll
Online Training Time zone: Europe/Paris * Enroll