
Explore the Fortinet FortiSIEM 40 sem bootcamp, covering architecture, sizing, ha and dr, installation, gui, logs, dashboards, reports, and licensing.
Explore FortiSIEM foundations and reference architectures, including rapid scale with supervisor, collectors, and workers; compare event databases (Clickhouse, Elasticsearch, local/NFS), and plan for on-prem, cloud, and MSSP deployments.
Size your FortiSIEM ClickHouse deployment using Fortinet's sizing guide, balancing minimum requirements, online retention, and storage with shards, replication, and hot and warm tiers.
Explore FortiSIEM's high availability and disaster recovery with the Clickhouse option, featuring a leader and followers supervisor architecture, optional load balancers, DNS redirection, and cross-site replication.
Install and configure Fortinet FortiSIEM 40 SIM supervisor all-in-one from an ova, allocate multi-disk storage, set network, run automated config, register the license, and configure Clickhouse storage.
Install and register a FortiCollector with the FortiSIEM supervisor, following the same steps as the collector installation, and configure hostname, IP, DNS, and login.
Explore a simplified FortiSIEM GUI with dashboards, analytics, incidents, CMDB, and case management. Navigate resources, rules, license, and settings to monitor health, updates, and event handling.
Install the FortiSIEM Windows agent, register it with the supervisor, and associate it with a collector; enable TLS 1.2 and disable disk fair share to enable running active status.
Explore the analytics page to search logs with keyword and attribute filters, adjust time ranges and chart types, and save and load custom layouts for repeat investigations.
Learn how Fortinet FortiSIEM incidents are triggered by rules across security, performance, availability, and change, and master incident creation through rule development and troubleshooting from logs to actions.
Enrich FortiSIEM by installing Sysmon, applying the config XML, and updating the agent template to include the Sysmon channel for high-fidelity Windows logs.
Explore how Fortinet FortiSIEM integrates Sysmon logs and adopts Sigma rules to detect malicious PowerShell behavior, and learn to develop and translate Sigma rules into FortiSIEM rules.
Translate a Sigma rule into a FortiSIEM rule by enabling command prompt and PowerShell auditing, mapping logs to FortiSIEM fields, and translating process creation events for detection.
Learn to deploy a FortiSIEM Linux agent, enable file integrity monitoring, and detect tampering via built-in FIM rules during an attack simulation on a Linux server.
FortiSIEM automatically discovers devices, applications, and users to build a CMDB, using SNMP, SSH, syslog, and NetFlow, with FortiGate as the example.
Configure and monitor FortiGate devices with FortiSIEM using SSH credentials to retrieve running configurations, enforce password authentication, and validate discoveries alongside SNP monitoring.
Enable syslog on FortiGate to forward traffic and system logs to FortiSIEM via GUI or CLI, set the supervisor IP, facility option, RFC 524 syslog format, and port 514 UDP.
Explore NetFlow discovery with FortiGate in FortiSIEM, and distinguish NetFlow from syslog. Configure CMDB groups, business SRV, and custom properties for precise asset tagging.
Design and use dashboards in FortiSIEM to monitor incidents and performance, and organize mission-critical devices into business services with dynamic grouping and dashboards.
Learn to locate and create FortiSIEM reports across 3000+ options, organize them in ABC folders, define conditions and display columns, run schedules, and save results for dashboards.
Extend a 40 SIM license by downloading the new license file from the 40 care website and uploading it on the admin license page to renew for one month.
Configure an NFS archive to extend FortiSIEM's event retention by linking an NFS server to the Clickhouse online storage and applying 3-month online and 12-month archive retention.
Validate archive data and learn to search archives in FortiSIEM, confirming online and archive synchronization on the analytics page and using retention policy to find logs beyond six months.
Add a 500 GB sixth disk to create a warm tier for Clickhouse and extend online retention from three to six months, while keeping the archive aligned with online storage.
Add a new data-plane interface to FortiSIEM, separate data and management networks, relocate the Linux agent, configure static routes and a FortiGate virtual IP, and test the isolated path.
Explore FortiSIEM licensing in depth, including perpetual vs subscription models, base and additional part numbers, devices and endpoints, advanced agents for log and FIM and UBA, with two case analyses.
Do you want to enter the SIEM field?
Do you want to learn one of the leaders SIEM technologies?
Do you want to understand the concepts and gain the handson on Fortinet FortiSIEM?
Then this course is designed for you. Through baby steps you will learn Fortinet FortiSIEM
FortiSIEM is a highly scalable multi-tenant Security Information and Event Management (SIEM) solution that provides real time infrastructure and user awareness for threat detection, analysis and reporting.
FortiSIEM provides an actionable security intelligence platform to monitor security, performance and compliance through a single pane of glass.
FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government.
Companies around the world use FortiSIEM for the following use cases:
Threat management and intelligence that provide situational awareness and anomaly detection
Alleviating compliance mandate concerns for PCI, HIPAA and SOX
Managing “alert overload”
Handling the “too many tools” reporting issue
Detect unusual user and entity behavior (UEBA) without requiring the Administrator to write complex rules.
Addressing the MSPs/MSSPs pain of meeting service level agreements
Fortinet FortiSIEM was previously known as FortiSIEM, AccelOps.
The course is covering below topics
- Introduction
- Foundations and Reference Architecture
- Scale-Out Architecture
- Distributed Event Correlation
- Clustering Architecture
- Licensing
- High Availability and Disaster Recovery - ClickHouse
- FortiSIEM Sizing - ClickHouse
- All-In-One Supervisor Installation
- FortiCollector Installation & Registeration
- FSM GUI simplified
- Windows Agent Installation, Registeration and Template Association
- Search via Analytics page
- Incidents, Rules Development and Troubleshooting
- Sysmon Log Integration into FortiSIEM
- Sigma Rules and Sysmon Rule Development
- Command Line_Powershell Auditing and Sigma Rule Translation
- Attack Scenario, File Integrity Monitoring and Linux Agent Installation
- Dashboards and Business Services
- Reports
- Device Discovery - FortiGate - SNMP, SSH, SYSLOG, and NETFLOW
- Discovery Settings, CMDB Groups, Business Services and Custom Properties
- Upload New License File
- NFS Archive and Retention Policy
- Validate and Search Archives
- ClickHouse Warm Tier disk addition to Extend Online Retention
- Splitting Data & Control Planes - Adding Network Interface to FortiSIEM
- Deep Dive on FortiSIEM Licensing and Part Numbers
Please note that FortiSIEM image download/license requires FortiCare entitlement or to be an active partner with Fortinet