Training Fortinet

Training goals

code: FT-FORTISIEMADM | version: 7.2.x

In this course, you will learn about FortiSIEM initial configurations and architecture, and the discovery of devices on the network. You will also learn how to collect performance information and aggregate it with syslog data to enrich the overall view of the health of your environment, use the configuration database to greatly facilitate compliance audits, and integrate FortiSIEM into your network awareness infrastructure.

 

Objectives

After completing this course, you should be able to:

  • Describe FortiSIEM key features and deployment architectures
  • Describe FortiSIEM indicators of compromise (IoC) and reputation check
  • Describe how FortiSIEM receives, collects, normalizes, and enriches logs
  • Describe event type classifications
  • Describe customer scaling with FortiSIEM collectors and collector high availability (HA)
  • Describe FortiSIEM agent architecture for managed security services providers (MSSP)
  • Describe various Fortinet Security Fabric integrations
  • Perform initial configurations, and role-based access management (RBAC)
  • Configure and troubleshoot asset discovery
  • View performance metrics and perform actions in the configuration management database (CMDB)
  • Deploy, assign, register, and upgrade collectors for MSSP customers
  • Configure and manage collector HA
  • Create and monitor critical business services
  • Analyze business services dashboards
  • Install and register FortiSIEM agents
  • Monitor agent status on the CMDB
  • Monitor events per second (EPS) usage
  • Configure event dropping rules
  • Configure identity and location information in the CMDB
  • Deploy AI-based user entity behavior analysis (UEBA)
  • Configure on-net and off-net detection, and FortiInsight watchlists
  • Configure zero-trust network access (ZTNA) integration
  • Create custom dashboards
  • Load, save, schedule, and import reports
  • Create and run CMDB and UEBA reports
  • Manage collection jobs
  • Define maintenance schedules
  • Monitor system status with FortiSIEM health check scripts
  • Collect and analyze system logs

 

Who Should Attend

Security professionals involved in the deployment, administration, maintenance, and troubleshooting of FortiSIEM devices should attend this course.

Conspect Show list

  1. Architecture
  2. SIEM and PAM Concepts
  3. Discovery
  4. Collectors
  5. Agents
  6. Fortinet Fabric Integration
  7. Reports and Dashboards
  8. Maintaining and Tuning
  9. Troubleshooting
Download conspect training as PDF

Additional information

Prerequisites

You should have an understanding of the topics covered in the FCF - FortiGate Operator course, or have equivalent experience.

Difficulty level
Duration 3 days
Certificate

The participants will obtain certificates signed by Fortinet (course completion).

This course prepares you also for the Fortinet FCP - FortiSIEM exam. By passing this exam, you will be awarded the associated exam badge.

Trainer

Fortinet Certified Trainer (FCT)

Additional informations

ISC2

  • CPE training hours: 7
  • CPE lab hours: 8
  • CISSP domains: Security Operations

Other training Fortinet | Fortinet Certified Professional (FCP)

Contact form

Please fill form below to obtain more info about this training.







* Fields marked with (*) are required !!!

Information on data processing by Compendium - Centrum Edukacyjne Spółka z o.o.

PRICE 2100 EUR

FORM OF TRAINING ?

 

TRAINING MATERIALS ?

 

SELECT TRAINING DATE

  • hybrid training: HYBRID
    • General information
    • Guaranteed dates
    • Last minute (-10%)
    • Language of the training
    • English
  • hybrid training: HYBRID
    • General information
    • Guaranteed dates
    • Last minute (-10%)
    • Language of the training
    • English
  • hybrid training: HYBRID
    • General information
    • Guaranteed dates
    • Last minute (-10%)
    • Language of the training
    • English
Book a training appointment
close

Traditional training

Sessions organised at Compendium CE are usually held in our locations in Kraków and Warsaw, but also in venues designated by the client. The group participating in training meets at a specific place and specific time with a coach and actively participates in laboratory sessions.

Dlearning training

You may participate from at any place in the world. It is sufficient to have a computer (or, actually a tablet, or smartphone) connected to the Internet. Compendium CE provides each Distance Learning training participant with adequate software enabling connection to the Data Center. For more information, please visit dlearning.eu site

close

Paper materials

Traditional materials: The price includes standard materials issued in the form of paper books, printed or other, depending on the arrangements with the manufacturer.

Electronic materials

Electronic materials: These are electronic training materials that are available to you based on your specific application: Skillpipe, eVantage, etc., or as PDF documents.

Ctab materials

Ctab materials: the price includes ctab tablet and electronic training materials or traditional training materials and supplies provided electronically according to manufacturer's specifications (in PDF or EPUB form). The materials provided are adapted for display on ctab tablets. For more information, check out the ctab website.

Upcoming Fortinet training

Training schedule Fortinet