LogRhythm Central Administration - Novice to Professional

所在平台: Udemy

课程主页: https://www.udemy.com/course/logrhythm-central-administration-novice-to-professional/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:LogRhythm中央管理 - 从初学者到专业人士 课程概述: 欢迎大家参加LogRhythm中央管理课程,我是您的讲师Adeel,一名拥有超过10年经验的网络安全工程师。如果您是LogRhythm的新手并且从未使用过它,那么这个课程非常适合您。课程假设您没有LogRhythm管理的先前知识,在课程结束时,您将对LogRhythm管理有深入的理解和专业知识。 课程目标是帮助您理解LogRhythm架构,并逐步执行LogRhythm SIEM的管理任务。该课程包含23个主要部分,覆盖了从LogRhythm架构、数据管理到用户配置文件、系统设置、数据掩码、报警规则、案例管理等多个主题,确保您能够掌握全面的LogRhythm管理技巧。 关键内容: 1. LogRhythm架构概述 2. 数据管理 3. 客户端和网络控制台 4. 实体管理 5. 列表管理 6. 知识库管理 7. 用户配置文件 8. 系统设置 9. 数据掩码 10. 全球日志处理规则(GLPR) 11. 客户端控制台中的日志调查 12. 报告中心 13. Second Look向导 14. 系统监控 15. 日志源 16. 高级智能引擎 17. 报警规则 18. 自定义仪表板创建 19. 报警管理 20. 案例管理 21. 数据库管理 22. 威胁情报 23. 配置评估与健康检查 通过本课程,您将获得针对LogRhythm综合性管理的实用技能,能够为日常工作提供支持。

课程评论(0条)

课程详情

Hello everyone and welcome to the LogRhythm Central Administration Course. I am glad you are here and I am glad you have enrolled.My name is Adeel and I am a Cyber Security Engineer with more than 10 years of experience. I will be your instructor on this course.If you are new to LogRhythm & you have never used LogRhythm before so this is the perfect course for you. I am assuming that you have no prior knowledge of LogRhythm Administration and by the time you are done with this course, you are going to have a very good understanding of LogRhythm Administration and you will have expertise in LogRhythm Administration.My goal in this course is to help you in understanding LogRhythm Architecture and step by step performing Administration task of LogRhythm SIEM.This is the course I wish had existed when I was first starting LogRhythm Deployment and Administration.This is not going to be just a quick how to get up and run. I really want to make sure to perform all the administrative tasks which will help you in your daily routine.I want to take a few minutes and I want to walk through to the curriculum because I need you to understand what you are going to learn before you jump into the course material.Let's go ahead and take a look at that right now.This course is broken up into 23 main sections and.Number one is LogRhythm Architecture Overview: In this section we will see what is LogRhythm SIEM. How Many components LogRhythm have. Also, we will see the workflow and life of log in LogRhythm.Number two is Data Management: In this section we will talk about LogRhythm classifications, common events and metadata. Also, we will see the LogRhythm data storage Architecture.Number three is Client console and web console: In this section we will perform a complete overview of client and web console and will have full understanding of client console and web console.Number four is Entities Management: In this section we will talk about LogRhythm entities and types. We will create entities and add network and host records in it. Also, we will create bulk entities by csv file.Number five is List management: in this section we will talk about list management in detail. We will create a list and also, we will retire and expire the list.Number six is Knowledge base management: in this section we will see the knowledge base architecture and also how to enable modules in knowledge base.Number seven is User's Profiles: In this section we will talk about user records and profile management. We will create users and roles. We will assign permissions to created users and limit them to entities.Number eight is System settings: in this section we will check the global risk base priority. How it works and also, we will see the RBP calculator.We will see the global settings and data management. We will perform active directory synchronization. We will use true identity tool to fetch users and groups data from active directory which helps in identifying users easily.we will change the component logging levels. And we will see service account and archive path.Number nine is data masking: in this section we will see what data masking is and how it works. We will apply data masking on live logs and also, we will talk about scenarios in which data masking must be applied.Number ten is global log processing rules (GLPR): In this section we will see what is GLPR. Why do we need GLPR and how to create GLPR.Number 11 is client console investigation: in this section we will see how to investigate logs in client console. How to create graphs on investigated logs in client console. How to use tail to see Realtime logs and how to create personal dashboard in client console.Number 12 is the Report center: in this section we will talk about report templates and report types. We will create a sample report on logs data. We will create a report package and we will see how to schedule a report package. Also, we will see how to get reports with Grafana.Number 13 is Second Look Wizard: in this section we will see how to restore logs with the help of Second Look Wizard. Also, we will restore logs with the help of LogRhythm archive utility. This is a very powerful utility to restore logs. I will show you how it works.Number 14 is System Monitor: in this section we will talk about types of system monitor agents. We will see how to deploy it and how to perform advanced configuration of the system monitor. Also, we will initiate smart responses with the help of system monitor agents.Number 15 is Log Source: in this section we will have a complete overview of LogRhythm supported log sources. We will integrate some log sources with LogRhythm like windows, Linux, web server and database. We will also see the method of bulk log source integration by which you can integrate hundreds of log sources in one go. Then we will talk about log source virtualization and see how it works.Number 16 is Advance Intelligence engine: in this section we will have a complete overview of AI engine and its common configurations. We will talk about rule block types. We will create new use cases and also modify some existing use cases. We will also execute smart responses from AI engine.Number 17 is Alarm Rules: in this section we will have a complete overview of alarm rules. We will see the difference between alarm rules and ai engine rules. We will also enable some alarm rules and test it.Number 18 is Custom dashboard creation: in this section we will create custom dashboard and add multiple widgets in it then we will modify that widget according to our requirement. Also, we will get help from Lucene query to customize the widgets and dashboard.Number 19 is alarm management: in this section we will see how to manage alarms and how to investigate the alarm and also how to link multiple alarms in one view.Number 20 is case management: in this section we will talk about case management. How to create a new case and how to add collaborator in case. How to set case priorities and how to check the status and work flow. Also, we will talk about case resolution.Number 21 is database management: In this section we will see how to create LogRhythm database backup job and also how to set up database cleanup job.Number 22 is Threat intelligence: in this section we will install threat intelligence tools and configure it. We will enable the threat intelligence module after installation and then we will associate it with the lists.Number 23 is Configuration assessment and Health check: in this section we will perform complete assessment and health check of LogRhythm integrated Log sources, MPE Rules and AI engine. We will also use LogRhythm diagnostic tool to check the health status of LogRhythm Components.

课程标签

0人关注该课程

主题相关的课程