FortiAnalyzer Analyst 7.4
In this course, you will learn the fundamentals of using FortiAnalyzer for centralized logging and reporting. You will learn how to configure and deploy FortiAnalyzer, and identify threats and attack patterns through logging, analysis, and reporting. Finally, you will examine the management of events, incidents, playbooks, and some helpful troubleshooting techniques. This course is part of preparation for the FCP Security Operations Badge exam.
Course Objectives
- After completing this course, you should be able to:
- Understand basic concepts and features
- Describe the purpose of collecting and securing logs
- View and search for logs in Log View and FortiView
- Understand FortiSoC features
- Manage events and event handlers
- Configure and analyze incidents
- Perform threat hunting tasks
- Understand outbreak alerts
- Describe how reports function within ADOMs
- Customize and create charts and datasets
- Customize and run reports
- Configure external storage for reports
- Attach reports to incidents
- Troubleshoot reports
- Understand playbook concepts
- Create and monitor playbooks
Target Audience
Anyone who is responsible for Fortinet Security Fabric analytics and automating tasks to detect and respond to cyberattacks using FortiAnalyzer should attend this course.
Course Outline
1. Introduction and Initial Configuration
2. Logging
3. FortiSoC—Events and Incidents
4. Reports
5. FortiSoC—Playbooks The ideal student will have:
- Familiarity with all topics presented in the NSE 4 FortiGate Security and NSE 4 FortiGate Infrastructure courses
- Knowledge of the SQL 'select' syntax is helpful.
System Requirements To access online content, students must have a computer with:
- A high-speed Internet connection
- An up-to-date web browser
- A PDF viewer
- Speakers or headphones
- (Optionally) a Java runtime environment (JRE)
Sorry! It looks like we haven’t updated our dates for the class you selected yet. There’s a quick way to find out. Contact us at 502.265.3057 or email info@training4it.com
Request a Date