BQ204G  IBM QRadar SIEM Advanced Topics

Duration:    2 Days

Level:          Intermediate

Audience:   Cyber-security Professional

Next Sessions
Start (YYYY-MM-DD) End (YYYY-MM-DD) Language Amount
2024-05-09 2024-05-10 English 1450 EUR 1590
2024-05-23 2024-05-24 English 1450 EUR 1604
2024-06-06 2024-06-07 English 1450 EUR 1618
2024-06-20 2024-06-21 English 1450 EUR 1632
2024-07-04 2024-07-05 English 1450 EUR 1646
2024-07-18 2024-07-19 English 1450 EUR 1660
2024-08-01 2024-08-02 English 1450 EUR 1674
2024-08-15 2024-08-16 English 1450 EUR 1688
2024-08-29 2024-08-30 English 1450 EUR 1702
2024-09-12 2024-09-13 English 1450 EUR 1716
2024-09-26 2024-09-27 English 1450 EUR 1730
2024-10-10 2024-10-11 English 1450 EUR 1744
2024-10-24 2024-10-25 English 1450 EUR 1758
2024-11-07 2024-11-08 English 1450 EUR 1772
2024-11-21 2024-11-22 English 1450 EUR 1786
2024-12-05 2024-12-06 English 1450 EUR 1800
2024-12-19 2024-12-20 English 1450 EUR 1814
Overview

QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses. 

This 2-day course walks you through various advanced topics about QRadar such as custom log sources, reference data collections and custom rules, X-Force data and the Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The course also discusses integration with IBM SOAR. Hands-on exercises reinforce the skills learned.

 

The lab environment for this course uses the IBM QRadar SIEM 7.4 platform.

Prerequisites

Students should be knowledgeable about the following topics:

  • IT infrastructure
  • IT security fundamentals
  • Linux
  • Windows
  • TCP/IP networking
  • Syslog
  • Foundational skills for the IBM QRadar Security Intelligence Platform (at least the skills that are taught in the IBM QRadar SIEM Foundations - BQ104 course)

 

  • Learn how to create custom log sources
  • Discover how to work with reference data collections and custom rules
  • Use X-Force data and Threat Intelligence app
  • Use the Use Case Manager app
  • Learn how to use UBA and QRadar Advisor
  • Discover Tuning
  • Explore Custom action scripts
  • Discuss Integration with IBM SOAR

Unit 1: Custom log sources

Unit 2: Reference data collections and custom rules

Unit 3: IBM X-Force Threat Intelligence in QRadar

Unit 4: User Behavior Analytics and Advisor with Watson

Unit 5: Tuning

Unit 6: Custom action scripts

Unit 7: IBM SOAR integration