Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Modern IBM QRadar 7.5 SIEM Administration
Rating: 4.1 out of 5(862 ratings)
5,692 students

Modern IBM QRadar 7.5 SIEM Administration

Understand modern best practices that will make you a better SIEM administrator
Created byDaniel Koifman
Last updated 6/2023
English

What you'll learn

  • Administer IBM's QRadar SIEM
  • Create rules and detections based on different telemetry sources
  • Troubleshoot various technical issues
  • Understand QRadar core services and functions

Course content

16 sections85 lectures8h 3m total length
  • A quick word from me to you1:43

    Learn a hands-on approach to modern IBM QRadar 7.5 siem administration with expert Daniel Coifman, designed to prepare you for the QRadar 7.5 certification.

  • Introduction & About the instructor1:52

    Explore IBM QRadar 7.5 SIEM basics, data ingestions, rules and offenses, and troubleshooting as you monitor security posture, detect and investigate threats, and respond to incidents through real-world scenarios.

  • Quick note about external resources - Important!0:14
  • Introduction to SIEM7:57

    Learn how security information and event management unifies log collection, centralized aggregation, long-term retention, and real-time correlation to generate alerts, reports, and dashboards for security monitoring.

  • Introduction to QRadar6:35

    Explore how curator, IBM QRadar's SIEM, ingests logs via the event collector, analyzes them with the event processor, and presents insights in the console with the app store built in.

  • Please read this BEFORE installing QRadar!0:33
  • Ingesting events from a Windows machine6:16

    Ingest Windows logs into QRadar using IBM wind collect, configure the endpoint source, view events in the log viewer, and verify by checking log source events.

  • Ingesting events from PfSense firewall2:44

    Configure pfSense to send logs to a QRadar 7.5 SIEM instance via remote syslog on port 514, view pfSense and Windows logs, and note that event parsing is covered later.

Requirements

  • Recommended basic knowledge of Computers, Networking, and Cyber Security.

Description

Hello everyone!

My name is Daniel Koifman, a recognized IBM Subject Matter Expert for QRadar, CASP+ Certified.

In this course, I will be showing you all of the most important subjects you need to know in order to be a skilled QRadar administrator, in addition to various real-world scenarios and best practices.

The course is divided into the following 15 sections:

  1. Introduction &  Installation

  2. QRadar overview

  3. Rules

  4. Working with Reference Data

  5. QRadar Administration - System Configuration

  6. QRadar Administration - Performance Optimization

  7. QRadar Administration - Data Source Configuration

  8. QRadar Administration - Accuracy Tuning

  9. QRadar Administration - User Management

  10. QRadar Administration - Reporting, Searching & Offense Management

  11. QRadar Administration - Tenants and Domains

  12. QRadar Administration - Troubleshooting

  13. Working with the QRadar Console

  14. Working with the API

  15. Practical Use Cases for New/Existing Deployments


Each section was carefully designed based on all of my experience working as a Senior Threat Detection engineer for fortune-500 and for MSSPs. This is the ONLY course with a detailed, in-depth practical use cases section, which will show you common problems that administrators are facing throughout the world. I developed this section based on my endless hours of trial & error and independent research, so I hope all of you can learn very useful things in the course, regardless of skill level!

Who this course is for:

  • SOC Analysts who work with QRadar
  • Detection Engineers
  • SIEM Engineers
  • QRadar Administrators