Course Overview
QRadar SIEM provides deep visibility into network, user, and application activity. It
provides collection, normalization, correlation, and secure storage of events, flows,
assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as
offenses.
This 2-day course walks you through various advanced topics about QRadar such as
custom log sources, reference data collections and custom rules, X-Force data and the
Threat Intelligence app, UBA and QRadar Advisor, tuning and custom action scripts. The
course also discusses integration with IBM SOAR. Hands-on exercises reinforce the
skills learned.
The lab environment for this course uses the IBM QRadar SIEM 7.4 platform.