ESM 101: NAM Enterprise Security Manager SIEM Administration

Training Overview

Enterprise Security Manager—the heart of our security information & event management (SIEM) solution—provides near real-time visibility into the activity on all your systems, networks, databases, & applications. This enables you to detect, correlate, & remedy threats in minutes across your entire IT infrastructure. This training prepares Enterprise Security Manager engineers & analysts to understand, communicate, & use the features provided by Enterprise Security Manager. Through hands-on lab exercises, you will learn how to optimize the Enterprise Security Manager by using recommended best practices & methodologies.

Duration: 4 days

Prerequisites

It is recommended that professionals have a working knowledge of networking & system administration concepts.

Audience Profile

This training is aimed at Enterprise Security Manager users, responsible for monitoring activity on systems, networks, databases, and applications, & for configuration & management of the Enterprise Security Manager solution. Attendees should have a working knowledge of networking & system administration concepts, a good understanding of computer security concepts, & a general understanding of networking & application software.

Learning Objectives:

This training focuses on enabling you to do the following: 

  • Define Enterprise Security Manager & SIEM concepts, identify appliances & their features, & describe the Enterprise Security Manager solution component architecture
  • Configure & customize receiver data sources & data source profiles
  • Effectively navigate the Enterprise Security Manager dashboard & create custom Enterprise Security Manager data views.
  • Customize event & flow aggregation fields on a per- signature basis, & define the advantages & nuances associated with event & flow aggregation.
  • Apply filters in views, create filter sets, use string normalization, & understand the basic syntax of regular expressions
  • Configure & deploy custom correlation rules within the correlation editor.

Content Outline

  • Training Introduction
  • Architecture Overview
  • Devices & Settings
  • ESM Interface & Views
  • Data Sources
  • Working with the ELM & ELS
  • Event Analysis
  • Aggregation
  • Watchlists & Policy Editor
  • Query Filters
  • Rule Correlation
  • Alarms
  • Workflow & Analysis
  • Reports
  • System Maintenance & Troubleshooting
  • Intro to Use Case Design

FAQs

Enterprise Security Manager—the heart of our security information & event management (SIEM) solution—provides near real-time visibility into the activity on all your systems, networks, databases, & applications. This enables you to detect, correlate, & remedy threats in minutes across your entire IT infrastructure. This training prepares Enterprise Security Manager engineers & analysts to understand, communicate, & use the features provided by Enterprise Security Manager.

Enterprise Security Management is the process of controlling configuration, deployment, & monitoring of security policy across multiple platforms & security point products.

This training focuses on enabling you to do the following: 

  • Define Enterprise Security Manager & SIEM concepts, identify appliances & their features, & describe the Enterprise Security Manager solution component architecture
  • Configure & customize receiver data sources & data source profiles
  • Effectively navigate the Enterprise Security Manager dashboard & create custom Enterprise Security Manager data views.
  • Customize event & flow aggregation fields on a per- signature basis, & define the advantages & nuances associated with event & flow aggregation.

It is recommended that professionals have a working knowledge of networking & system administration concepts.

Radiant Tech Learning has a data centre containing a Virtual Training environment for the purpose of professional hand-on-practice. Professionals can easily access these labs over Cloud with the help of a remote desktop connection. Radiant virtual labs provide you with the flexibility to learn from anywhere in the world & at any time

The learners will be enthralled as we engage them the real-world & Oriented industry projects during the training program. These projects will improve your skills & knowledge, & you will gain a better experience. These real-time projects will help you a lot in your future tasks & assignments.

You can request a refund if you do not wish to enroll in the training.

Radiant has highly intensive selection criteria for Technology Trainers & Professionals who deliver training programs. Our trainers & professionals undergo rigorous technical & behavioural interview & assessment processes before they are on-boarded in the company.

Our Technology experts/trainers & professionals carry deep-dive knowledge in the technical subject & are certified by the OEM.

Our training programs are practically oriented with 70% – 80% hands-on training technology tools. Our training program focuses on one on one interaction with each professional, the latest content in the curriculum, real-time projects & case studies during the training program.

Our faculty will provide you with the knowledge of each training from the fundamental level in an easy way & you are free to ask your doubts any time from your respective faculty.

Our trainers have patience & ability to explain difficult concepts in a simplistic way with depth & width of knowledge.

To ensure quality learning, we provide a support session even after the training program.

Send a Message.


  • Enroll