Modern IBM QRadar 7.5 SIEM Administration
- Description
- Curriculum
- FAQ
- Reviews
Hello everyone!
My name is Daniel Koifman, a recognized IBM Subject Matter Expert for QRadar, CASP+ Certified.
In this course, I will be showing you all of the most important subjects you need to know in order to be a skilled QRadar administrator, in addition to various real-world scenarios and best practices.
The course is divided into the following 15 sections:
-
Introduction & Installation
-
QRadar overview
-
Rules
-
Working with Reference Data
-
QRadar Administration – System Configuration
-
QRadar Administration – Performance Optimization
-
QRadar Administration – Data Source Configuration
-
QRadar Administration – Accuracy Tuning
-
QRadar Administration – User Management
-
QRadar Administration – Reporting, Searching & Offense Management
-
QRadar Administration – Tenants and Domains
-
QRadar Administration – Troubleshooting
-
Working with the QRadar Console
-
Working with the API
-
Practical Use Cases for New/Existing Deployments
Each section was carefully designed based on all of my experience working as a Senior Threat Detection engineer for fortune-500 and for MSSPs. This is the ONLY course with a detailed, in-depth practical use cases section, which will show you common problems that administrators are facing throughout the world. I developed this section based on my endless hours of trial & error and independent research, so I hope all of you can learn very useful things in the course, regardless of skill level!
-
1A quick word from me to youVideo lesson
-
2Introduction & About the instructorVideo lesson
-
3Quick note about external resources - Important!Text lesson
-
4Introduction to SIEMVideo lesson
-
5Introduction to QRadarVideo lesson
-
6Installing QRadarVideo lesson
-
7Ingesting events from a Windows machineVideo lesson
-
8Ingesting events from PfSense firewallVideo lesson
-
12Requirements for upcoming application installationsVideo lesson
-
13Use Case Manager, Rules and Building BlocksVideo lesson
-
14Using AQL inside rulesVideo lesson
-
15Troubleshooting rulesVideo lesson
-
16Optimizing rulesVideo lesson
-
17Identifying expensive rulesVideo lesson
-
18Practical Example #1 - SIGMA rulesVideo lesson
-
19Practical Example #2 - Firewall rulesVideo lesson
-
33XPath queriesVideo lesson
-
34Log source managementVideo lesson
-
35Event coalescingVideo lesson
-
36Log source groupsVideo lesson
-
37Exporting event dataVideo lesson
-
38Custom log source types (DSM) / Event MappingsVideo lesson
-
39Custom AQL PropertiesVideo lesson
-
40Custom event propertiesVideo lesson
-
60Connecting to the ConsoleVideo lesson
-
61QRadar filesystemText lesson
-
62Running AQL inside the ConsoleVideo lesson
-
63Troubleshooting servicesVideo lesson
-
64Troubleshooting events rate and connectivityVideo lesson
-
65Performing a manual deployVideo lesson
-
66Reverting SSL certificate to locally signedVideo lesson
-
67Deleting a rule directly from the consoleVideo lesson
-
68Useful Console commands listText lesson
-
71Alerting on non-reporting log sourcesVideo lesson
-
72Alerting on non-reporting domainsVideo lesson
-
73Alerting on disabled custom propertiesVideo lesson
-
74Alerting on disk usage exceeded warning/maximum thresholdVideo lesson
-
75Alerting on events droppedVideo lesson
-
76DSM "Failed to load data" errorVideo lesson
-
77Creating useful dashboards with PulseVideo lesson
-
78Working with Threat IntelligenceVideo lesson
-
79Working with QRadar Deployment IntelligenceVideo lesson
-
80Mandatory steps after upgrading Console CPUVideo lesson
-
81Logs are being truncated / splitVideo lesson
-
82Section NotesText lesson
-
83Notes about updating applicationsText lesson

External Links May Contain Affiliate Links read more