
Install and configure Fortinet FortiSIEM 40 SIM supervisor all-in-one from an ova, allocate multi-disk storage, set network, run automated config, register the license, and configure Clickhouse storage.
Install and register a FortiCollector with the FortiSIEM supervisor, following the same steps as the collector installation, and configure hostname, IP, DNS, and login.
Enrich FortiSIEM by installing Sysmon, applying the config XML, and updating the agent template to include the Sysmon channel for high-fidelity Windows logs.
Explore how Fortinet FortiSIEM integrates Sysmon logs and adopts Sigma rules to detect malicious PowerShell behavior, and learn to develop and translate Sigma rules into FortiSIEM rules.
Translate a Sigma rule into a FortiSIEM rule by enabling command prompt and PowerShell auditing, mapping logs to FortiSIEM fields, and translating process creation events for detection.
Learn to deploy a FortiSIEM Linux agent, enable file integrity monitoring, and detect tampering via built-in FIM rules during an attack simulation on a Linux server.
FortiSIEM automatically discovers devices, applications, and users to build a CMDB, using SNMP, SSH, syslog, and NetFlow, with FortiGate as the example.
Configure and monitor FortiGate devices with FortiSIEM using SSH credentials to retrieve running configurations, enforce password authentication, and validate discoveries alongside SNP monitoring.
Learn to locate and create FortiSIEM reports across 3000+ options, organize them in ABC folders, define conditions and display columns, run schedules, and save results for dashboards.
Configure an NFS archive to extend FortiSIEM's event retention by linking an NFS server to the Clickhouse online storage and applying 3-month online and 12-month archive retention.
Add a new data-plane interface to FortiSIEM, separate data and management networks, relocate the Linux agent, configure static routes and a FortiGate virtual IP, and test the isolated path.
Do you want to enter the SIEM field?
Do you want to learn one of the leaders SIEM technologies?
Do you want to understand the concepts and gain the handson on Fortinet FortiSIEM?
Then this course is designed for you. Through baby steps you will learn Fortinet FortiSIEM
FortiSIEM is a highly scalable multi-tenant Security Information and Event Management (SIEM) solution that provides real time infrastructure and user awareness for threat detection, analysis and reporting.
FortiSIEM provides an actionable security intelligence platform to monitor security, performance and compliance through a single pane of glass.
FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government.
Companies around the world use FortiSIEM for the following use cases:
Threat management and intelligence that provide situational awareness and anomaly detection
Alleviating compliance mandate concerns for PCI, HIPAA and SOX
Managing “alert overload”
Handling the “too many tools” reporting issue
Detect unusual user and entity behavior (UEBA) without requiring the Administrator to write complex rules.
Addressing the MSPs/MSSPs pain of meeting service level agreements
Fortinet FortiSIEM was previously known as FortiSIEM, AccelOps.
The course is covering below topics
- Introduction
- Foundations and Reference Architecture
- Scale-Out Architecture
- Distributed Event Correlation
- Clustering Architecture
- Licensing
- High Availability and Disaster Recovery - ClickHouse
- FortiSIEM Sizing - ClickHouse
- All-In-One Supervisor Installation
- FortiCollector Installation & Registeration
- FSM GUI simplified
- Windows Agent Installation, Registeration and Template Association
- Search via Analytics page
- Incidents, Rules Development and Troubleshooting
- Sysmon Log Integration into FortiSIEM
- Sigma Rules and Sysmon Rule Development
- Command Line_Powershell Auditing and Sigma Rule Translation
- Attack Scenario, File Integrity Monitoring and Linux Agent Installation
- Dashboards and Business Services
- Reports
- Device Discovery - FortiGate - SNMP, SSH, SYSLOG, and NETFLOW
- Discovery Settings, CMDB Groups, Business Services and Custom Properties
- Upload New License File
- NFS Archive and Retention Policy
- Validate and Search Archives
- ClickHouse Warm Tier disk addition to Extend Online Retention
- Splitting Data & Control Planes - Adding Network Interface to FortiSIEM
- Deep Dive on FortiSIEM Licensing and Part Numbers
Please note that FortiSIEM image download/license requires FortiCare entitlement or to be an active partner with Fortinet