Course: ESM200I-76
ArcSight ESM Administrator & Analyst
Virtual Instructor Led Training
Authorised OpenText Trainer
Difficulty Rating
Course Duration: 5 Days
The participants will obtain certificates signed by OpenText (course completion). This course prepares for ESM200 - ArcSight ESM Administrator and Analyst ASP Exam
The exam is administered on the last day of the instructor-led class and is a hands-on, performance based exam. The VILT offering does not include a certification exam.
Course Description
In this introductory course you learn how to use the ArcSight console and ArcSight Command Center to monitor security events, configure ESM, manage users, and manage ESM network intelligence resources. You will also be introduced to triaging and resolving cases with SOAR.
Highlights:
Investigate security events
Configure security content
Upon successful completion of this course, you should be able to:
Make ArcSight ESM operational upon initial installation
Describe how ESM works in the context of your network
Create user accounts • Implement built-in content
Populate ESM with your network and assets to identify endpoints involved in an event
Create site-specific business-oriented views
Investigate, identify, analyze, and remediate exposed security issues
Use workflow management to provide real-time incident response and escalation tracking
Modify and run standard reports to provide situational awareness and network status
Establish ESM peering across multiple ESM instances
Perform distributed event search and content management
Modules
ESM Overview
Command Center
ESM Console
Installing and Configuring ArcSight Connectors
ArcSight Marketplace
Schema, Fieldsets, & Active Channels
Filters
Dashboards & Data Monitors
Rules & Lists
User Administration
Notifications
Incident Response and Automation with SOAR
Queries & Query Viewers
Reports
Content Management & Peering
Event Search
Intended Audience
This course is intended for ESM System Administrators and Analysts.
Recommended Skills
Working knowledge of enterprise security, event and log management