Udemy - Modern IBM QRadar 7.5 SIEM Administration
- Category Other
- Type Tutorials
- Language English
- Total size 3.5 GB
- Uploaded By freecoursewb
- Downloads 478
- Last checked 6 hours ago
- Date uploaded 2 years ago
- Seeders 4
- Leechers 4
Infohash : 0C0B21B0FD8A2B212228A8D4B20F7842673D52A3
Modern IBM QRadar 7.5 SIEM Administration 
https://DevCourseWeb.com
Published 4/2023
Created by Daniel Koifman
MP4 | Video: h264, 1280x720 | Audio: AAC, 44.1 KHz, 2 Ch
Genre: eLearning | Language: English | Duration: 84 Lectures ( 7h 59m ) | Size: 3.5 GB
Understand modern best practices that will make you a better SIEM administrator
What you'll learn
Administer IBM's QRadar SIEM
Create rules and detections based on different telemetry sources
Troubleshoot various technical issues
Understand QRadar core services and functions
Requirements
Recommended basic knowledge of Computers, Networking, and Cyber Security.
Files:
[ DevCourseWeb.com ] Udemy - Modern IBM QRadar 7.5 SIEM Administration- Get Bonus Downloads Here.url (0.2 KB) ~Get Your Files Here ! 1. Introduction & Installation
- 1. A quick word from me to you.mp4 (38.6 MB)
- 2. Introduction & About the instructor.mp4 (8.4 MB)
- 3. Quick note about external resources - Important!.html (0.4 KB)
- 4. Introduction to SIEM.mp4 (37.2 MB)
- 5. Introduction to QRadar.mp4 (41.7 MB)
- 5.1 QRadar_Architecture_-_Deep_Dive.pdf (774.6 KB)
- 5.2 QRadar_Architecture_-_General.pdf (1.1 MB)
- 6. Installing QRadar.mp4 (24.9 MB)
- 6.1 ISO Download Link.html (0.3 KB)
- 7. Ingesting events from a Windows machine.mp4 (46.7 MB)
- 7.1 Wincollect Download Link.html (0.3 KB)
- 7.2 Wincollect IBM documentation.html (0.1 KB)
- 8. Ingesting events from PfSense firewall.mp4 (25.1 MB)
- 8.1 Sending PfSense Logs to QRadar.html (0.1 KB)
- 1. Managing reports.mp4 (92.0 MB)
- 1.1 Report management.html (0.1 KB)
- 2. Utilizing different search types.mp4 (41.5 MB)
- 2.1 AQL Query structure.html (0.1 KB)
- 2.2 AQL search string examples.html (0.1 KB)
- 2.3 Ariel Query Language.html (0.1 KB)
- 2.4 Converting a saved search to an AQL string.html (0.1 KB)
- 2.5 Querying with dynamic search.html (0.1 KB)
- 2.6 Sample AQL queries.html (0.1 KB)
- 3. Managing offenses.mp4 (41.2 MB)
- 3.1 How QRadar Offense Renaming works.html (0.2 KB)
- 3.2 Offense management.html (0.1 KB)
- 4. Sharing content among users.mp4 (19.5 MB)
- 4.1 Sharing Dashboard Items.html (0.1 KB)
- 4.2 Sharing report groups.html (0.1 KB)
- 1. Differentiating between network hierarchy and domain definition.mp4 (33.9 MB)
- 1.1 Guidelines for defining your network hierarchy.html (0.1 KB)
- 1.2 Network hierarchy updates in a multitenant deployment.html (0.2 KB)
- 2. Managing domains and tenants.mp4 (43.5 MB)
- 2.1 Domain segmentation.html (0.1 KB)
- 2.2 Domains and log sources in multitenant environments.html (0.1 KB)
- 2.3 QRadar Multi-tenancy, Domains and Log Source Groups.html (0.1 KB)
- 3. Monitoring license usage.mp4 (29.1 MB)
- 3.1 Monitoring license usage in multitenant deployments.html (0.1 KB)
- 4. Assigning users to tenants.mp4 (9.4 MB)
- 4.1 Security profiles.html (0.1 KB)
- 4.2 User roles.html (0.1 KB)
- 1. Responding to and dealing with system notifications.mp4 (47.6 MB)
- 1.1 QRadar system notifications.html (0.1 KB)
- 2. Troubleshooting common issues.html (1.0 KB)
- 3. Troubleshooting applications.mp4 (79.6 MB)
- 3.1 How to use Recon to troubleshoot QRadar applications.html (0.1 KB)
- 4. Troubleshoot service performance.mp4 (17.2 MB)
- 4.1 Using ThreadTop to determine QRadar process load.html (0.1 KB)
- 1. Connecting to the Console.mp4 (6.6 MB)
- 2. QRadar filesystem.html (2.2 KB)
- 3. Running AQL inside the Console.mp4 (29.1 MB)
- 4. Troubleshooting services.mp4 (44.5 MB)
- 4.1 Core services and the impact of restarting services.html (0.1 KB)
- 5. Troubleshooting events rate and connectivity.mp4 (33.1 MB)
- 6. Performing a manual deploy.mp4 (16.2 MB)
- 6.1 Full Deployment Failed.html (0.1 KB)
- 7. Reverting SSL certificate to locally signed.mp4 (19.2 MB)
- 7.1 Reverting to certificates that are generated by the QRadar local CA.html (0.2 KB)
- 8. Deleting a rule directly from the console.mp4 (23.0 MB)
- 9. Useful Console commands list.html (2.8 KB)
- 1. QRadar API basics.mp4 (39.3 MB)
- 1.1 Python utility functions for QRadar.html (0.1 KB)
- 1.2 QRadar API endpoint documentation and supported versions.html (0.2 KB)
- 2. Example - Python script with QRadar API.mp4 (45.3 MB)
- 2.1 QRadar API Example.html (0.1 KB)
- 1. Alerting on non-reporting log sources.mp4 (27.9 MB)
- 10. Mandatory steps after upgrading Console CPU.mp4 (21.9 MB)
- 11. Logs are being truncated split.mp4 (26.8 MB)
- 11.1 Truncated Logs.html (0.1 KB)
- 12. Section Notes.html (1.2 KB)
- 13. Notes about updating applications.html (0.9 KB)
- 2. Alerting on non-reporting domains.mp4 (47.6 MB)
- 3. Alerting on disabled custom properties.mp4 (41.8 MB)
- 4. Alerting on disk usage exceeded warningmaximum threshold.mp4 (25.9 MB)
- 5. Alerting on events dropped.mp4 (17.8 MB)
- 6. DSM Failed to load data error.mp4 (18.4 MB)
- 7. Creating useful dashboards with Pulse.mp4 (66.1 MB)
- 7.1 Monitor EPS and Log Sources (1).json (3.5 KB)
- 8. Working with Threat Intelligence.mp4 (92.6 MB)
- 8.1 App Link.html (0.1 KB)
- 9. Working with QRadar Deployment Intelligence.mp4 (46.7 MB)
- 9.1 App Link.html (0.1 KB)
- 1. End Notes.mp4 (6.3 MB)
- 1. User Interface.mp4 (38.7 MB)
- 2. Log Activity basic searching.mp4 (78.2 MB)
- 3. QRadar Services.mp4 (100.7 MB)
- 3.1 QRadar Core Services.html (0.1 KB)
- 1. Requirements for upcoming application installations.mp4 (14.9 MB)
- 2. Use Case Manager, Rules and Building Blocks.mp4 (229.9 MB)
- 2.1 Everything you need to know about QRadar Rules.html (0.2 KB)
- 2.2 Investigating QRadar rules and building blocks.html (0.2 KB)
- 2.3 QRadar building blocks.html (0.1 KB)
- 2.4 Use Case Manager.html (0.1 KB)
- 3. Using AQL inside rules.mp4 (82.1 MB)
- 4. Troubleshooting rules.mp4 (38.5 MB)
- 4.1 Troubleshooting rules.html (0.1 KB)
- 5. Optimizing rules.mp4 (45.0 MB)
- 5.1 Optimizing Rules.html (0.2 KB)
- 6. Identifying expensive rules.mp4 (97.2 MB)
- 6.1 Troubleshooting Custom Rule performance.html (0.3 KB)
- 7. Practical Example #1 - SIGMA rules.mp4 (261.0 MB)
- 7.1 SIGMA Rules Github.html (0.1 KB)
- 8. Practical Example #2 - Firewall rules.mp4 (69.2 MB)
- 1. Different types of Reference Data.mp4 (59.9 MB)
- 1.1 Creating reference data collections by using the command line.html (0.2 KB)
- 1.2 Reference data query examples.html (0.1 KB)
- 1.3 Types of reference data collections.html (0.1 KB)
- 2. Using Reference Data with the default user interface.mp4 (22.0 MB)
- 3. Integrating Reference Data and Rules.mp4 (88.0 MB)
- 4. Advice on dealing with massive amounts of Reference Data.mp4 (22.4 MB)
- 1. Managed hosts.mp4 (32.5 MB)
- 1.1 Managed hosts.html (0.1 KB)
- 2. Network hierarchy.mp4 (58.5 MB)
- 2.1 Defining your network hierarchy.html (0.1 KB)
- 3. Automatic updates.mp4 (26.3 MB)
- 3.1 Automatic updates.html (0.1 KB)
- 3.2 Configuring automatic update settings.html (0.1 KB)
- 3.3 Important auto update server changes for administrators.html (0.1 KB)
- 4. Event retention.mp4 (39.6 MB)
- 4.1 About event retention buckets.html (0.1 KB)
- 5. Backup and recovery.mp4 (19.9 MB)
- 5.1 Backup QRadar configurations and data.html (0.1 KB)
- 6. Custom offense Email templates.mp4 (53.5 MB)
- 6.1 Configuring event and flow custom email notifications.html (0.2 KB)
- 1. Index management.mp4 (36.1 MB)
- 1.1 Configuring the retention period for payload indexes.html (0.2 KB)
- 1.2 Enabling indexes.html (0.1 KB)
- 1.3 Enabling payload indexing to optimize search times.html (0.2 KB)
- 2. Configuring resource restrictions.mp4 (44.5 MB)
- 2.1 Resource restrictions in distributed environments.html (0.2 KB)
- 2.2 Restrictions to prevent resource-intensive searches.html (0.2 KB)
- 3. Routing Rules.mp4 (40.3 MB)
- 3.1 Configuring routing rules to forward data.html (0.1 KB)
- 3.2 Routing options for rules.html (0.1 KB)
- 1. XPath queries.mp4 (36.3 MB)
- 1.1 How to use Microsoft Event Viewer to create an XPath Query.html (0.2 KB)
- 1.2 XPath Query Troubleshooting.html (0.1 KB)
- 2. Log source management.mp4 (53.0 MB)
- 2.1 Adding a log source to receive events.html (0.1 KB)
- 2.2 Protocol configuration options.html (0.1 KB)
- 2.3 Testing log sources.html (0.1 KB)
- 3. Event coalescing.mp4 (33.1 MB)
- 3.1 How does coalescing work in QRadar.html (0.1 KB)
- 4. Log source groups.mp4 (41.5 MB)
- 4.1 Log source groups.html (0.1 KB)
- 5. Exporting event data.mp4 (54.2 MB)
- 5.1 Exporting events.html (0.1 KB)
- 6. Custom log source types (DSM) Event Mappings.mp4 (96.9 MB)
- 6.1 DSM Editor overview.html (0.1 KB)
- 7. Custom AQL Properties.mp4 (47.9 MB)
- 7.1 QRadar AQL Custom Properties.html (0.1 KB)
- 8. Custom event properties.mp4 (57.8 MB)
- 8.1 Creating a custom property.html (0.1 KB)
- 8.2 Custom event and flow properties.html (0.1 KB)
- 8.3 Defining custom properties by using custom property expressions.html (0.2 KB)
- 8.4 Modifying or deleting a custom property.html (0.1 KB)
- 1. Configuring MaxMind GeoIP.mp4 (39.1 MB)
- 1.1 Configuring a MaxMind account for geographic data updates.html (0.1 KB)
- 2. Verifying GeoIP Changes.mp4 (13.6 MB)
- 2.1 Configuring a MaxMind account for geographic data updates.html (0.1 KB)
- 3. Configuring X-Force Integration.mp4 (45.0 MB)
- 3.1 Enabling the X-Force Threat Intelligence feed.html (0.1 KB)
- 3.2 IBM X-Force Exchange plug-in for QRadar.html (0.1 KB)
- 3.3 IBM X-Force integration.html (0.1 KB)
- 1. Managing users.mp4 (12.2 MB)
- 1.1 User accounts.html (0.1 KB)
- 2. User roles.mp4 (15.4 MB)
- 2.1 User roles.html (0.1 KB)
- 3. Security profiles.mp4 (33.6 MB)
- 3.1 Security profiles.html (0.1 KB)
- 4. Managing user authentication & authorization.mp4 (20.1 MB)
- 4.1 User authentication.html (0.1 KB)
- Bonus Resources.txt (0.4 KB)
There are currently no comments. Feel free to leave one :)
Code:
- udp://tracker.torrent.eu.org:451/announce
- udp://tracker.tiny-vps.com:6969/announce
- http://tracker.foreverpirates.co:80/announce
- udp://tracker.cyberia.is:6969/announce
- udp://exodus.desync.com:6969/announce
- udp://explodie.org:6969/announce
- udp://tracker.opentrackr.org:1337/announce
- udp://9.rarbg.to:2780/announce
- udp://tracker.internetwarriors.net:1337/announce
- udp://ipv4.tracker.harry.lu:80/announce
- udp://open.stealth.si:80/announce
- udp://9.rarbg.to:2900/announce
- udp://9.rarbg.me:2720/announce
- udp://opentor.org:2710/announce