Understand modern best practices that will make you a better SIEM administrator
Hello everyone!
What you’ll learn
- Administer IBM’s QRadar SIEM.
- Create rules and detections based on different telemetry sources.
- Troubleshoot various technical issues.
- Understand QRadar core services and functions.
Course Content
- Introduction & Installation –> 8 lectures • 34min.
- QRadar overview –> 3 lectures • 22min.
- Rules –> 8 lectures • 1hr 41min.
- Working with Reference Data –> 4 lectures • 28min.
- QRadar Administration – System Configuration –> 6 lectures • 31min.
- QRadar Administration – Performance Optimization –> 3 lectures • 18min.
- QRadar Administration – Data Source Configuration –> 8 lectures • 54min.
- QRadar Administration – Accuracy Tuning –> 3 lectures • 12min.
- QRadar Administration – User Management –> 4 lectures • 13min.
- QRadar Administration – Reporting, Searching & Offense Management –> 4 lectures • 26min.
- QRadar Administration – Tenants and Domains –> 4 lectures • 18min.
- QRadar Administration – Troubleshooting –> 4 lectures • 17min.
- Working with the QRadar Console –> 9 lectures • 28min.
- Working with the API –> 2 lectures • 13min.
- Practical Use Cases for New/Existing Deployments –> 13 lectures • 1hr 1min.
- Course End – Congratulations! –> 1 lecture • 2min.
Requirements
Hello everyone!
My name is Daniel Koifman, a recognized IBM Subject Matter Expert for QRadar, CASP+ Certified.
In this course, I will be showing you all of the most important subjects you need to know in order to be a skilled QRadar administrator, in addition to various real-world scenarios and best practices.
The course is divided into the following 15 sections:
- Introduction & Installation
- QRadar overview
- Rules
- Working with Reference Data
- QRadar Administration – System Configuration
- QRadar Administration – Performance Optimization
- QRadar Administration – Data Source Configuration
- QRadar Administration – Accuracy Tuning
- QRadar Administration – User Management
- QRadar Administration – Reporting, Searching & Offense Management
- QRadar Administration – Tenants and Domains
- QRadar Administration – Troubleshooting
- Working with the QRadar Console
- Working with the API
- Practical Use Cases for New/Existing Deployments
Each section was carefully designed based on all of my experience working as a Senior Threat Detection engineer for fortune-500 and for MSSPs. This is the ONLY course with a detailed, in-depth practical use cases section, which will show you common problems that administrators are facing throughout the world. I developed this section based on my endless hours of trial & error and independent research, so I hope all of you can learn very useful things in the course, regardless of skill level!