Skip to content

FÜR EINZELPERSONEN

open
Logo

FÜR EINZELPERSONEN

open
Logo
FACHBEREICH
open
Logo
UNTERFACHBEREICH
open
Logo
UNTERFACHBEREICH
open
Logo
SEMINARE
open
Basic
Advanced
Expert
Sonstige Seminare
SEMINAR
NV-5420
Micro Focus
Background
5 Tage
Background
Standorte
Background
Termine

ArcSight-ESM-Advanced Analyst with Certified Expert Exam

Kein Badge verfügbar.

Ihr Seminar buchen

Seminarinhalte

Ziele

open
Upon successful completion of this course, you should be able to: Navigate ArcSight ESM console and command center to correlate, investigate, analyze and remediate both exposed and obscure threats Construct ArcSight variables to provide advanced analysis of the event stream Develop ArcSight lists and rules to allow advanced correlation activities Optimize event-based data monitors to provide real-time viewing of event traffic and anomalies Design new report templates and create functional reports Find events through the search tools

Inhalte

open

Module 1: ESM Overview


  • Identify ESM Architecture
  • Describe the content of the ArcSight Event Schema
  • List the phases of the ArcSight Event Lifecycle
  • Describe the event processing and schema population performed during each phase of the event lifecycle
  • List the resources and tools applicable to specific phases of the event lifecycle


Module 2: Command Center


  • Access the ArcSight ESM Command Center
  • Monitor Usage Metrics
  • View System Metrics
  • Use the SOC/MITRE Dashboards
  • Access and use Active Lists
  • Utilize Field Sets


Module 3: ArcSight Console


  • Launch the ArcSight Console
  • Identify toolbar components and their functions
  • List the different views available in the Viewer panel
  • Identify three methods to access Console Help
  • Describe the Reference Resources and their characteristics
  • Identify ESM Console preference options
  • Customize your ESM Console


Module 4: Active Channels


  • Create a new Active Channel
  • View the details of an event
  • Identify Dynamic and Static Active Channels


Module 5: Filters


  • Describe Filter types and usage
  • Add, edit and save Filters to an Active Channel
  • Define the Common Conditions Editor


Module 6: Variable Customization


  • Describe functions available in Variables
  • Create both Local and Global Variables
  • Promote Local to Global Variables
  • Share Global Variables among multiple resources


Module 7: Data Monitors and Dashbords


  • Identify Data Monitor types and functions
  • Create a Data Monitor
  • Access and Use Dashboards
  • Modify Dashboard Data Monitor Layouts


Module 8: ESM Lists


  • Describe the differences between Active and Session Lists
  • Create and validate Active and Session List integration Rules


Module 9: ESM Rules


  • Create and validate the following:
  • Rule behavior
  • Brute Force Login Attempt and Successful rules
  • Light Weight rules and Pre-Persistent rules


Module 10: Query Viewers Authoring


  • Define Queries
  • Describe Query Viewers
  • Explain the advantages of using Query Viewers
  • Create the following functions with Query Viewers:
  • Drilldowns
  • Baselines
  • Reports
  • Dashboard views


Module 11: ESM Reports


  • List the components in the Report Workflow
  • List the different types of Reports
  • Run a Report from the Navigator panel
  • View an Archive Report from the Navigator panel
  • Set up a scheduled Report job
  • Build a custom Report
  • Build a custom Trend Report


Module 12: Unified Event Search Tools


  • Describe how keyword, field-based and pipeline searches are performed
  • Describe how search results are displayed
  • Use the unified Search page to initiate any type of search
  • Use Search Helper and Search Builder features to save time constructing search expressions
  • Load, modify, and save search filters and saved searches
  • Enable peer ESM and Logger instances for searching

Badge

open

Kein Badge verfügbar.

Vorkenntnisse

open
To be successful in this course, you should have the following prerequisites or knowledge: Common security devices such as IDS and firewalls Common network device functions, such as routers, switches, and hubs TCP/IP functions such as CIDR blocks, subnets, addressing, and communications Basic Windows operating system tasks and functions Possible attack activities, such as scans, man in the middle, sniffing, DoS, and possible abnormal activities, such as worms, Trojans, and viruses SIEM terminology, such as threat, vulnerability, risk, asset, exposure, and safeguards Completed the ArcSight ESM Administrator and Analyst course or 6 months experience administering ArcSight ESM

Zielgruppe

open
This course is intended for analysts responsible for: Defining their organization’s security objectives Building or using advanced content to correlate, view and respond to those security objectives.

Methoden

open
KONTAKT

Martin Heubeck

Sales Gruppenseminare und Inhouse
Mo – Fr 8:00 – 17:00 Uhr
E-Mail senden
+49 891 22216949
+49 800 3060303

JETZT UNVERBINDLICHEN BERATUNGSTERMIN BUCHEN

open
„Im Beratungsprozess lege ich besonderen Wert darauf, die besonderen Bedürfnisse und Ziele Ihres Unternehmens genau zu verstehen. Gemeinsam mit Ihnen entwickle ich passgenaue Lösungen, die sowohl fachliche Anforderungen erfüllen als auch die persönliche Weiterentwicklung der Mitarbeitenden fördern – immer praxisnah und auf Augenhöhe.“
Background
Interesse an einem Inhouse-Seminar?
Wir bieten dieses Thema auch als geschlossenes Firmentraining an. Schulen Sie ganze Abteilungen auf einmal – inhaltlich perfekt an Ihren Bedarf angepasst. Führen Sie das Seminar flexibel in Ihren eigenen Räumen oder online durch und sparen Sie wertvolle Zeit sowie Reisekosten.

Inhouse-Angebot anfragen

open
Background
Mann mit Laptop
Seien Sie nicht nur am Ergebnis orientiert. Sondern auch am Erlebnis.
Manager Institut Swoosh
Top Seminare im Rechenzentrum, Netzwerke & Cloud
Microsoft Windows PowerShell For Administrators
2 Bewertungen

Seminar entdecken

Kurs Linux - Systemadministration und Netzwerkadministration Kurs
2 Bewertungen

Seminar entdecken

Active Directory unter Windows Server 2025 (2022)
2 Bewertungen

Seminar entdecken

SharePoint 2019 Power User
2 Bewertungen

Seminar entdecken

Advanced Automated Administration with Windows PowerShell
2 Bewertungen

Seminar entdecken

Netzwerktechnik Grundlagen
1 Bewertung

Seminar entdecken

Implementing Cisco QOS (Quality of Service)

Seminar entdecken

Erstellen verteilter Apps mit .NET Aspire

Seminar entdecken

Fortbildung Linux - Linux und der Name Server: BIND/Domain Name Server(DNS)

Seminar entdecken

Windows 11 und Windows Server 2022 - Kompakt für Administratoren

Seminar entdecken

Windows 11 für Anwender

Seminar entdecken

Automatisieren von Azure Load Testing mithilfe von GitHub

Seminar entdecken

Kontaktverläufe mit Dynamics 365 Customer Insights erstellen und verwalten

Seminar entdecken

Configure a Dynamics 365 customer experience solution

Seminar entdecken

Administration und Bereitstellung von Microsoft Dynamics 365

Seminar entdecken

Servervirtualisierung: Planung, Einrichtung, Administration virtueller Server

Seminar entdecken

ONTAP Data Protection Administration

Seminar entdecken

ONTAP Cluster Administration

Seminar entdecken

UNIX Fortbildung - UNIX Systemsicherheit Workshop

Seminar entdecken

UNIX Kompaktworkshop

Seminar entdecken

Unsere Bestsellerseminare
Manager University Logo
Werdet die agilen Managerinnen und Manager von morgen.
Ziel: Zertifizierter Abschluss, um sich klar am Markt vor den anderen positionieren zu können; nutzen Sie Ihre Aufstiegschance für Weiterführung Ihrer Karriere. Persönliche und fachspezifische Persönlichkeitsentwicklung.

ZUR MANAGER INSTITUT UNIVERSITY

open
MEINUNGEN