Training Fortinet

Training goals

code: FT-FORTISIEMANALYST | version: 7.2.x

In this course, you will learn how to use FortiSIEM to search, enrich, and analyze events from customers in a managed security service provider (MSSP) organization. You will learn how to perform real-time and historical searches, and build advanced queries. You will also learn how to perform analysis and remediation of security incidents.

 

Objectives

After completing this course, you should be able to:

  • Identify business drivers for using SIEM tools
  • Describe how FortiSIEM solves common cybersecurity challenges
  • Describe the main components and the unique database architecture on FortiSIEM
  • Perform real-time and historical searches
  • Define structured search operators and search conditions
  • Reference the CMDB data in structured searches
  • Add display fields and columns
  • Build queries from search results and events
  • Build nested queries and lookup tables
  • Build rule subpatterns and conditions
  • Identify critical interfaces and processes
  • Create rules using baselines
  • Analyze a profile report
  • Analyze anomalies against baselines
  • Analyze the different incident dashboard views
  • Refine and tune incidents
  • Clear an incident
  • Export an incident report
  • Create time-based and pattern-based clear conditions
  • Configure automation policies
  • Configure remediation scripts and actions
  • Differentiate between manual and automatic remediation
  • Configure notifications

 

Who Should Attend

Security professionals responsible for the detection, analysis, and remediation of security incidents using FortiSIEM should attend this course.

Conspect Show list

  1. Introduction to FortiSIEM
  2. Analytics
  3. Nested Queries and Lookup Tables
  4. Rules and Subpatterns
  5. Performance Metrics and Baselines
  6. Incidents
  7. Clear Conditions and Remediation
Download conspect training as PDF

Additional information

Prerequisites

You must have an understanding of the topics covered in the following courses, or have equivalent experience:

  • FCF - FortiGate Fundamentals
  • FortiSIEM Administrator
Difficulty level
Duration 2 days
Certificate

The participants will obtain certificates signed by Fortinet (course completion).

This course prepares you also for the FCP - FortiSIEM Analyst exam. By passing this exam, you will be awarded the associated exam badge.

Trainer

Fortinet Certified Trainer (FCT)

Additional informations

ISC2

  • CPE training hours: 6
  • CPE lab hours: 5
  • CISSP domains: Security Operations

Other training Fortinet | Fortinet Certified Professional (FCP)

Contact form

Please fill form below to obtain more info about this training.







* Fields marked with (*) are required !!!

Information on data processing by Compendium - Centrum Edukacyjne Spółka z o.o.

PRICE 1400 EUR

FORM OF TRAINING ?

 

TRAINING MATERIALS ?

 

SELECT TRAINING DATE

  • hybrid training: HYBRID
    • General information
    • Guaranteed dates
    • Last minute (-10%)
    • Language of the training
    • English
  • hybrid training: HYBRID
    • General information
    • Guaranteed dates
    • Last minute (-10%)
    • Language of the training
    • English
Book a training appointment
close

Traditional training

Sessions organised at Compendium CE are usually held in our locations in Kraków and Warsaw, but also in venues designated by the client. The group participating in training meets at a specific place and specific time with a coach and actively participates in laboratory sessions.

Dlearning training

You may participate from at any place in the world. It is sufficient to have a computer (or, actually a tablet, or smartphone) connected to the Internet. Compendium CE provides each Distance Learning training participant with adequate software enabling connection to the Data Center. For more information, please visit dlearning.eu site

close

Paper materials

Traditional materials: The price includes standard materials issued in the form of paper books, printed or other, depending on the arrangements with the manufacturer.

Electronic materials

Electronic materials: These are electronic training materials that are available to you based on your specific application: Skillpipe, eVantage, etc., or as PDF documents.

Ctab materials

Ctab materials: the price includes ctab tablet and electronic training materials or traditional training materials and supplies provided electronically according to manufacturer's specifications (in PDF or EPUB form). The materials provided are adapted for display on ctab tablets. For more information, check out the ctab website.

Upcoming Fortinet training

Training schedule Fortinet