Koenig/Security Incidents and event management with qradar (Advanced)

Download Course Contents

Security Incidents and event management with qradar (Advanced) Course Overview

Security Information and Event Management with QRadar provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses. In this class, you learn to navigate the user interface and how to investigate crimes. You hunt and examine the data from which QRadar SIEM concluded a suspicious activity. Hands-on exercises reinforce the skills learned.

Audience: This basic class is suited for security analysts, security technical architects, offense managers, network administrators, and system administrators.

This is a Rare Course and it can be take up to 3 weeks to arrange the training.

The 1-on-1 Advantage

Flexible Dates

  • • Choose Start Date
  • • Reschedule After Booking
  • • Weekend / Evening Option

4-Hour Sessions

You will learn:

Module 1: Using administration tools
  • QRadar SIEM reminder
  • Admin tab
  • Advanced list options
  • About the deployment editor
  • Host Context overview
  • Configuring Host Context
  • Adding a managed host
  • Deployment Editor: Configuring collectors
  • Auto update overview
  • Configuration auto updates: Basic tab
  • Configuring auto updates: Advanced tab
  • System and license management
  • Uploading and allocating a license
  • Reverting an allocation unlocks a license
  • Replacing a license by allocating a new one
  • Activating a license
  • Exporting license key information
  • Web-based System Administration Interface
  • QRadar Console Settings
  • QRadar System Settings
  • Global System Notifications
  • Managing custom offense close reasons
  • Authorized services
  • Using authorized services
  • Authorized services URLs
  • Network hierarchy overview
  • QRadar SIEM network hierarchy
  • Network hierarchy recommendations
  • Adding a network hierarchy
  • Building a group node versus leaf node
  • Remote networks and services overview
  • Adding a remote networks object
  • Managing remote services
  • Adding remote services
  • Asset profiles overview
  • Server discovery overview
  • Importing and exporting assets
  • Viewing scanners
  • Reference Set overview
  • Reference Set elements
  • Index management overview
  • Enabling indexes
  • User account overview
  • Creating user roles
  • Security profile overview
  • Security profile: Permission Precedence tab
  • Security profile: Networks and Log Sources tab
  • Editing a security profile
  • Configuring authentication
  • Introduction to data backups
  • Creating an on-demand configuration backup
  • Creating a backup schedule
  • Restoring backup archives
  • Using event and flow retention buckets
  • Configure an event retention bucket
  • Configuring flow retention buckets
  • Collecting data: Data sources
  • Log sources through traffic analysis
  • Adding log sources
  • Adding log source extensions
  • Log source parsing order
  • Flow data overview
  • Adding a flow source
  • Adding a flow source with asymmetric routing
  • Flow source aliases
  • Adding a flow source alias
  • About Windows log collection agents
  • WinCollect
  • Adaptive Log Exporter (ALE)
  • Snare agent
  • WMI protocol
  • Installing WinCollect
  • Creating an authorized service for the WinCollect agent
  • Installing the WinCollect agent software
  • Applying the machine name, Service Token, and console IP
  • Adding a log source to the WinCollect agent
  • Installing an Adaptive Log Exporter (ALE) agent
  • Configuring the ALE agent
  • Configuring the destination
  • Custom log sources
  • Required tools
  • Integrating unsupported Log Sources
  • Obtaining a sample log
  • Obtaining a log sample from a remote location
  • Uploading the LSX_Template.xml file
  • Creating a universal DSM log source
  • Testing the universal DSM log source
  • Mapping the unknown log records
  • Example of a LEEF log record event category
  • Creating a regular expression to extract the log source EventID from a LEEF event
  • Creating an appropriate regular expression
  • Common regular expressions
  • Regular expression recommendations
  • Using capture groups
  • Inserting regular expression patterns in the LSX
  • Cleaning the LSX template
  • Testing modifications to the LSX document
  • About QRadar Identifiers (QIDS)
  • Creating a new QID entry with qidmap_cli.sh
  • Mapping the Log Source ID to custom QIDs
  • Mapping Log Source Event IDs to existing QIDs
  • Testing the mapping
  • Points to remember about mapping
  • About QRadar SIEM rules
  • About QRadar SIEM Building Blocks
  • Using Building Blocks
  • Combining Building Blocks to capture specific events or flows
  • Linking tests
  • Linking tests in the correct order
  • The custom rule engine (CRE)
  • Attack scenario example
  • Detecting the attack with a rule
  • Creating rules overview
  • Rule that captures account creation
  • Rule that captures access to sensitive data
  • Rule that captures account deletion
  • Combining rules to capture a sequence of events
  • Using time-series and anomaly rules
  • Conficker example
  • Creating a search to accumulate data
  • Creating a time series for the search
  • Creating an anomaly rule
  • A CRE event is the default response
  • Creating a custom rule to catch the pattern
  • Custom rule response and action
  • False positive overview
  • Example 1: Suspicious access to sensitive data
  • Example 2a: Botnet access: Determining the rule
  • Example 2b: Searching for contributing events
  • Example 2c: False positive wizard.
  • Example 3a: Capturing events first, deciding later
  • Example 3b: Finding rules with high offense counts
  • Example 3c: Using the rule to capture events in a report
  • Example 3d: Analyzing the report
  • Example 4a: Analyzing offenses by category
  • Example 4b: Listing the offenses by category § Example 4c: Finding the first rule that triggered
  • Example 4c: Finding the first rule that triggered
  • Example 4d: Determining a strategy to eliminate the false positive
  • Example 4e: Modifying the appropriate Building Blocks
  • Example 4f: Fine tune the rule that triggered the offense
  • Tuning guidelines
  • Commonly edited Building Blocks
  • Tuning by changing rules
  • Adjusting and enabling additional rules
  • Reference Maps overview
  • Reference Maps use cases
  • Using Reference Maps on the command line
  • Using ReferenceDataUtil.sh
  • Using Reference Maps in the user interface
  • Using Reference Maps in searches
  • Sample use case of Reference Map of Sets
  • Creating a Reference Map of Sets
  • Creating a CRE rule
  • Creating a group by search
  • Alternative to a CRE rule
  • Creating an ADE rule
  • Managing the Reference Map of Sets
  • Using the CRE response
  • Deleting records from the command line
Live Online Training (Duration : 16 Hours) Fee On Request
We Offer :
  • 1-on-1 Public - Select your own start date. Other students can be merged.
  • 1-on-1 Private - Select your own start date. You will be the only student in the class.

4 Hours
8 Hours
Week Days

Start Time : At any time

12 AM
12 PM

1-On-1 Training is Guaranteed to Run (GTR)
Group Training
Date On Request
Course Prerequisites
  • Qradar Foundation

Upon Completion of this Course, you will accomplish following:-

  • Identify the role and capabilities of the QRadar SIEM licensed program.
  • Describe how QRadar SIEM collects data and performs vulnerability assessment.
  • Find out how to navigate and customize the dashboard tab.
  • Determine how to investigate the data incorporated in an offense and react to an offense.
  • Discover  how to detect, filter, and group events in society to gain vital insights about the crime.
  • Discover how to make and edit a search that monitors the events of suspicious hosts.
  • Learn  how asset profiles are created and updated, and how to apply them every bit part of an offense investigation.
  • Determine how to investigate the flows that give to an offense, create and tune false positives, and investigate superfluous.
  • Discover  how to find custom rules in the QRadar SIEM console, assign actions and responses to the rule, and how to configure rules.
  • Determine how to utilize charts and use advanced filters to analyze specific activities in your surroundings.

Give an edge to your career with Other Technologies certification training courses. Students can join the classes for Security Information and Event Management with QRadar (Administration) at Koenig Campus located at New Delhi, Bengaluru, Shimla, Goa, Dehradun, Dubai & Instructor-Led Online.

Student Feedback  (Check Koenig Feedback on Trustpilot)

Q1 Say something about the Trainer? Q2 How is Koenig different from other training Companies? Q3 Will you come back to Koenig for training ?

Student Name Country Feedback Rating
Abu United States A1. Yes, she was very clear & a strong mastery of both English & Azure platforms hence following was easy. She was also patient and was answering every question asked, she also shared material & tips on how to pass the exam, Well done, and keep it up.
Nick Barker United States A1. Calm and understanding, she not only kept the course running well but also took time to help those with lots of questions. Very well done.
Robin Johnson United States A2. Individual attention during training, excellent customer service and coordination. Neha has been ever so helpful and is definitely an asset to Koenig.
Shivani Prasad United States A1. The trainer was great and his teaching methods were incredible. He used different teaching methods to ensure I was learning well. A fun trainer with lots of patience and understanding.
Adam United States A1. The trainer was very knowledgeable and well prepared about the presentation/training subject, with a positive attitude towards students and making every effort in answering questions during the training session. Top-notch service!
Suresh United States A1. Exceptional... recommend to everyone!
Shyam Vaddakapett United States A1. My trainer, Mohit Kakkar was excellent as he focused on hands-on assignments to supplement the concepts of AZ 900. The training coordinator Jasmeet as well as the ops manager Sheshadri are also very professional and customer-centric. I recommend Koenig for training courses, and I will take some more courses with them soon.
Gilles Chirlias United States A1. Chavi was a great teacher, I have learned a lot from her. I would like to have her for the next training, which would be the AZ 301 and AZ 500.
Abdulrahman Saad Alshahrani United States A1. Excellent trainer. I will take another course with him someday. He deserves a good appreciation from his Manager.
Anonymous United States https://www.youtube.com/watch?v=sqC40CFfBYI

Request More Information

Add Name and Email Address of participant (If different from you)


1-on-1 Public - Select your start date. Other students can be merged.
1-on-1 Private - Select your start date. You will be the only student in the class.
Yes, course requiring practical include hands-on labs.
You can buy online from the page by clicking on "Buy Now". You can view alternate payment method on payment options page.
Yes, you can pay from the course page and flexi page.
Yes, the site is secure by utilizing Secure Sockets Layer (SSL) Technology. SSL technology enables the encryption of sensitive information during online transactions. We use the highest assurance SSL/TLS certificate, which ensures that no unauthorized person can get to your sensitive payment data over the web.
We use the best standards in Internet security. Any data retained is not shared with third parties.
You can request a refund if you do not wish to enroll in the course.
To receive an acknowledgment of your online payment, you should have a valid email address. At the point when you enter your name, Visa, and other data, you have the option of entering your email address. Would it be a good idea for you to decide to enter your email address, confirmation of your payment will be emailed to you.
After you submit your payment, you will land on the payment confirmation screen.It contains your payment confirmation message. You will likewise get a confirmation email after your transaction is submitted.
We do accept all major credit cards from Visa, Mastercard, American Express, and Discover.
Credit card transactions normally take 48 hours to settle. Approval is given right away; however,it takes 48 hours for the money to be moved.
Yes, we do accept partial payments, you may use one payment method for part of the transaction and another payment method for other parts of the transaction.
Yes, if we have an office in your city.
Yes, we do offer corporate training More details
Yes, we do.
Yes, we also offer weekend classes.
Yes, Koenig follows a BYOL(Bring Your Own Laptop) policy.
It is recommended but not mandatory. Being acquainted with the basic course material will enable you and the trainer to move at a desired pace during classes.You can access courseware for most vendors.
Yes, this is our official email address which we use if a recipient is not able to receive emails from our @koenig-solutions.com email address.
Buy-Now. Pay-Later option is available using credit card in USA and India only.
You will receive the digital certificate post training completion via learning enhancement tool after registration.
Yes you can.
Yes, we do. For details go to flexi
You can pay through debit/credit card or bank wire transfer.
Yes you can request your customer experience manager for the same.
Yes, fee excludes local taxes.
Yes, we do.
The Fee includes:
  • Courseware
  • Remote Labs
Schedule for Group Training is decided by Koenig. Schedule for 1-on-1 is decided by you.
In 1-on-1 you can select your own schedule, other students can be merged but you select the schedule. Choose 1-on-1 if published schedule do not meet your requirement. If you also want a private session, opt for 1-on-1 Public.
No, it is not included.

Prices & Payments

Yes of course.
Yes, We are

Travel and Visa

Yes we do after your registration for course.

Food and Beverages



Says our CEO-
“It is an interesting story and dates back half a century. My father started a manufacturing business in India in the 1960's for import substitute electromechanical components such as microswitches. German and Japanese goods were held in high esteem so he named his company Essen Deinki (Essen is a well known industrial town in Germany and Deinki is Japanese for electric company). His products were very good quality and the fact that they sounded German and Japanese also helped. He did quite well. In 1970s he branched out into electronic products and again looked for a German name. This time he chose Koenig, and Koenig Electronics was born. In 1990s after graduating from college I was looking for a name for my company and Koenig Solutions sounded just right. Initially we had marketed under the brand of Digital Equipment Corporation but DEC went out of business and we switched to the Koenig name. Koenig is difficult to pronounce and marketeers said it is not a good choice for a B2C brand. But it has proven lucky for us.” – Says Rohit Aggarwal (Founder and CEO - Koenig Solutions)
All our trainers are fluent in English . Majority of our customers are from outside India and our trainers speak in a neutral accent which is easily understandable by students from all nationalities. Our money back guarantee also stands for accent of the trainer.
Medical services in India are at par with the world and are a fraction of costs in Europe and USA. A number of our students have scheduled cosmetic, dental and ocular procedures during their stay in India. We can provide advice about this, on request.
Yes, if you send 4 participants, we can offer an exclusive training for them which can be started from Any Date™ suitable for you.