Under attack?
Security administrator programme

Administering a SIEM platform

For the teams running the platform day to day: keeping it available, making sure the sources are reporting, and diagnosing problems without waiting for a supplier.

  • 4 to 5 days
  • Security administrators
  • Dedicated lab
  • 70% hands-on
Who this programme is for

You run the platform, not just the alerts

This programme is aimed at security administrators, systems engineers and operations staff who are responsible for the platform itself: its availability, its capacity, its sources and its retention.

By the end you should be able to install a collector, onboard a new source, understand why an index is filling up and restore an interrupted feed without outside help. Everything is practised on a dedicated lab, where a mistake carries no consequences.

Prerequisites

Linux or Windows system administration, a working understanding of networking and logging. No prior SIEM knowledge is required.

Skills covered

  • Describe the platform architecture and the role of each component
  • Install and configure agents and collectors
  • Onboard a source and validate its normalisation
  • Size indexes and manage retention
  • Manage access, roles and service accounts
  • Back up and restore the configuration
  • Diagnose a loss of collection and fix it
  • Track licence consumption
Syllabus

Five modules

ModuleContentFormat
1 · ArchitecturePlatform components, data flows, standalone and distributed deployment models, sizing.Lecture and case study
2 · InstallationSetting up the components, initial configuration, securing access, certificates.Hands-on
3 · Data sourcesAgents, collectors, formats, field extraction, normalisation to a common schema.Hands-on
4 · OperationsIndexes, retention, capacity planning, backup and restore, licence management.Hands-on
5 · DiagnosisSilent sources, parsing drift, saturation, reading internal logs, investigation method.Problem-solving workshops
Practical information

Organisation

Duration4 to 5 days, depending on the platform and the group’s starting level
AudienceSecurity administrators, systems engineers, operations staff
Group size4 to 8 participants, to guarantee access to the exercises
EnvironmentA dedicated lab platform, separate from any production environment
Platforms coveredSplunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh
FormatOn site, remotely in a virtual classroom, or a mix of both
Follow-upCourse material kept by participants and a remote consolidation session included

Let us build your session

Tell us which platform you operate and where your teams stand. We adapt the syllabus and send you a quotation.