QRadar EDR: Integrating with QRadar SIEM [TDS_BQ530G]

Total time

QRadar EDR: Integrating with QRadar SIEM [TDS_BQ530G]

Global Knowledge Network Training Ltd.
Logo Global Knowledge Network Training Ltd.
Provider rating: starstarstarstarstar_border 7.7 Global Knowledge Network Training Ltd. has an average rating of 7.7 (out of 3 reviews)

Need more information? Get more details on the site of the provider.

Starting dates and places

This product does not have fixed starting dates and/or places.

Description

OVERVIEW

In this course you learn how to integrate QRadar EDR and SIEM by creating an API application in QRadar EDR and by adding a new log source in QRadar SIEM to add endpoint detection and alerts to QRadar SIEM. Integrating QRadar EDR and SIEM amplifies the power of QRadar XDR (extended detection and response) by leveraging AI and automation opportunities. Having advanced and automated response capabilities enables analysts to focus on the fight in front of them.

This course applies to version 3.12 of the on-premises IBM Security QRadar EDR offering.

Virtual Learning

This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training …

Read the complete description

Frequently asked questions

There are no frequently asked questions yet. If you have any more questions or need help, contact our customer service.

OVERVIEW

In this course you learn how to integrate QRadar EDR and SIEM by creating an API application in QRadar EDR and by adding a new log source in QRadar SIEM to add endpoint detection and alerts to QRadar SIEM. Integrating QRadar EDR and SIEM amplifies the power of QRadar XDR (extended detection and response) by leveraging AI and automation opportunities. Having advanced and automated response capabilities enables analysts to focus on the fight in front of them.

This course applies to version 3.12 of the on-premises IBM Security QRadar EDR offering.

Virtual Learning

This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.

OBJECTIVES

In this course you learn to do these activities:

  • Configure an API application in QRadar EDR
  • Install a new log source in QRadar SIEM
  • Configure the correct protocol for a log source in QRadar SIEM
  • Analyze endpoint alerts from the SIEM dashboard using data from EDR

AUDIENCE

This course is tailored to IT security analysts in a Security Operations Center (SOC) environment who are tasked with endpoint protection and threat hunting, as well as QRadar EDR administrators, incident responders, and managed service security providers (MSSP).

CONTENT

Unit 1: Integrating with QRadar SIEM

  • Configure an API application in QRadar EDR
  • Install a new log source in QRadar SIEM
  • Configure the correct protocol for a log source in QRadar SIEM
  • Analyze endpoint alerts from the SIEM dashboard using data from EDR

Unit 2: QRadar EDR - integrating with QRadar SIEM - Lab

  • Exercise 1 - Configuring QRadar EDR and QRadar SIEM integration
  • Exercise 2 - BitTorrent is run on an endpoint
  • Exercise 3 – Malware detected (tryme.exe)
There are no reviews yet.
    Share your review
    Do you have experience with this course? Submit your review and help other people make the right choice. As a thank you for your effort we will donate £1.- to Stichting Edukans.

    There are no frequently asked questions yet. If you have any more questions or need help, contact our customer service.