FortiSIEM Analyst (FORT-SIEM)

 

Who should attend

Security professionals responsible for the detection, analysis, and remediation of security incidents using FortiSIEM should attend this course.

Prerequisites

You must have an understanding of the topics covered in the following courses, or have equivalent experience.

  • FCF - FortiGate Fundamentals
  • !

Course Objectives

After completing this course, you should be able to:

  • Describe how FortiSIEM solves common cybersecurity challenges
  • Describe the main components and the unique database architecture on FortiSIEM
  • Perform real-time and historical searches
  • Define structured search operators and search conditions
  • Reference the CMDB data in structured searches
  • Add display fields and columns
  • Build queries from search results and events
  • Build nested queries and lookup tables
  • Build rule subpatterns and conditions
  • Identify critical interfaces and processes
  • Create rules using baselines
  • Analyze a profile report
  • Analyze anomalies against baselines
  • Analyze the different incident dashboard views
  • Refine and tune incidents
  • Clear an incident
  • Export an incident report
  • Create time-based and pattern-based clear conditions
  • Configure automation policies
  • Configure remediation scripts and actions
  • Differentiate between manual and automatic remediation
  • Configure notifications

Course Content

In this course, you will learn how to use FortiSIEM to search, enrich, and analyze events from customers in a managed security service provider (MSSP) organization. You will learn how to perform real-time and historical searches, and build advanced queries. You will also learn how to perform analysis and remediation of security incidents.

This course is part of the preparation for the FCP - FortiSIEM 7.2 Analyst certification exam. This exam is part of the Fortinet Certified Professional - Security Operations certification track.

Prezzo & Delivery methods

Online Training

Durata
2 Giorni

Prezzo
  • Su richiesta
Formazione in Aula

Durata
2 Giorni

Prezzo
  • Su richiesta
 

Schedulazione

Data garantita:   Fast Lane garantirà il corso indipendentemente dal numero dei partecipanti
Instructor-led Online Training:   Corso Online con Istruttore If you have any questions about our online courses, feel free to contact us via phone or Email anytime.

Contattaci per avere informazioni sulle date disponibili in Italiano.

Inglese

Fuso orario: Central European Summer Time (CEST)   ±1 Ora

Online Training 4 Giorni Fuso orario: Central European Summer Time (CEST) Lingua Corso: Inglese Erogazione garantita Half-day class

3 ore spostamento del fuso orario

Online Training Fuso orario: Gulf Standard Time (GST) Lingua Corso: Inglese