BQ203G | IBM Security QRadar SIEM Advanced Topics | Training Course | IBM. Skip to main Content

IBM Security QRadar SIEM Advanced Topics

  • Course Code BQ203G
  • Duration 2 days

Course Delivery

Public Classroom Price

eur1.590,00

excl. VAT

Request Group Training Add to Cart

Course Delivery

This course is available in the following formats:

  • Public Classroom

    Traditional Classroom Learning

  • Virtual Learning

    Learning that is virtual

Request this course in a different delivery format.

Course Overview

Top

This is an advanced course for the QRadar Analyst and Administrator and is a follow-on to BQ103G.

This course uses the IBM QRadar SIEM 7.3 platform for lab exercises.

Course Schedule

Top

Target Audience

Top

This course is useful for Security administrators, Security technical architects, Offense managers, Professional services using QRadar SIEM, QRadar SIEM administrators.

Course Objectives

Top

The course objctives are:

  • Create custom log sources to utilize events from uncommon sources
  • Create, maintain, and use reference data collections
  • Develop and manage custom rules to detect unusual activity in your network
  • Develop and manage custom action scripts to for automated rule reponse
  • Develop and manage anomoly detection rules to detect when unusual network traffic patterns occur

Course Content

Top

In this course, you will see:

  • Module 1: Creating log source types
  • Module 2: Leveraging reference data collections
  • Module 3: Developing custom rules
  • Module 4: Creating Custom Action Scripts
  • Module 5: Developing Anomaly Detection Rules

Course Prerequisites

Top

Before this course, you should be familiar with:

  • IT infrastructure
  • IT security fundamentals
  • Linux
  • Microsoft Windows
  • TCP/IP networking
  • Log files and events
  • Network flows

You should also have completed the IBM QRadar SIEM Foundations course.

Cookie Control toggle icon