SolarWinds Security Event Manager (SIEM) Network Security

所在平台: Udemy

课程主页: https://www.udemy.com/course/solarwinds-security-event-manager-sem-complete-course-2021/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程简介:SolarWinds 安全事件管理器 (SIEM) 网络安全** 本课程将深入介绍 SolarWinds Security Event Manager (SEM),一款专为资源受限的 IT 和安全专业人员设计的经济高效的 SIEM 解决方案。SEM 能够提供强大的威胁检测、自动化的事件分析与响应,以及合规性报告,覆盖您整个 IT 基础设施。 **核心功能与优势:** * **一体化解决方案:** SEM 将日志管理、威胁检测、日志规范化与关联分析、日志转发、报告、文件完整性监控、用户活动监控、USB 设备检测与阻止、威胁情报以及主动响应等功能整合在一个易于部署、管理和使用的虚拟设备中。 * **降低复杂性与成本:** 相较于许多其他企业级 SIEM 解决方案,SEM 在提供所需功能的同时,显著降低了复杂度和成本。 * **强化现有安全体系:** SEM 作为一款安全信息与事件管理 (SIEM) 虚拟设备,能够为您的现有安全产品增值,并提升在管理、监控安全策略和保障措施方面的效率。 * **实时威胁检测与响应:** SEM 能够访问日志数据以进行取证和故障排除,并提供管理日志数据的工具。它能够实时分析收集到的日志,并在问题造成进一步损害之前向您发出通知。 * **应对高级持续性威胁 (APT):** SEM 的关联引擎能够识别由软件安装、身份验证事件和网络流量等一系列网络事件组合而成的高级威胁活动,并及时向您报告异常情况。 **课程目标:** 通过本课程的学习,您将能够: * 理解 SIEM 的核心概念及其在网络安全中的重要性。 * 熟练掌握 SolarWinds SEM 的各项功能,包括日志管理、威胁检测、事件关联和响应。 * 了解如何利用 SEM 提升组织的事件响应能力和合规性。 * 学习如何配置和优化 SEM 以适应不同的网络环境。 **本课程适用于:** * 网络安全分析师 * IT 管理员 * 安全运营中心 (SOC) 成员 * 任何希望加强组织网络安全防御能力的专业人士

课程评论(0条)

课程详情

Thousands of resource-constrained IT and security pros rely on SolarWinds Security Event Manager (SEM) for affordable and efficient threat detection, automated incident analysis and response, and compliance reporting for their IT infrastructure. Our SIEM solution combines log management, threat detection, normalization and correlation, forwarding, reporting, file integrity monitoring, user activity monitoring, USB detection and prevention, threat intelligence, and active response in a virtual appliance that's easy to deploy, manage, and use. We've designed our SIEM to provide the functionality you need without the complexity and cost of most other enterprise SIEM solutions.SolarWinds Security Event Manager (formerly Log & Event Manager), is a security information and event management (SIEM) virtual appliance that adds value to existing security products and increases efficiencies in administering, managing, and monitoring security policies and safeguards on your network.SEM provides access to log data for forensic and troubleshooting purposes, and tools to help you manage log data. SEM leverages collected logs, analyzes them in real time, and notifies you of a problem before it causes further damage.For example, advanced persistent threats can come from a combination of network events such as software installations, authentication events, and inbound and outbound network traffic. Log files contain all information about these events. The SEM correlation engine identifies advanced threat activity, and then notifies you of any anomalies.Best Security information and event management SIEM / Best SIEM Tool

课程标签

0人关注该课程

主题相关的课程