This course provides you with the knowledge required to use advanced ArcSight ESM content to find and correlate event information, perform actions such as notifying stakeholders, graphically analyze event data, and report on security incidents. You will familiarize and/or reinforce your understanding of the advanced correlation capabilities within ArcSight ESM that provide a significant edge in detecting active attacks.
This course covers ArcSight security problem solving methodology using advanced ESM content to find, track, and re-mediate security incidents. During the training, you will use variables and correlation activities, customize report templates for dynamic content, and customize Dashboards to monitor incidents.
Duration: 4 days
Delivery Type: Instructor Led (ILT) and Virtual Instructor Led (VILT)
Level: Analyst
Audience: This course is intended for Analysts and Content Engineers who:
• Define their organization’s security objectives
• Build or using advanced content to correlate, view and respond to those security objectives
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox