Administering a SIEM platform
For the teams running the platform day to day: keeping it available, making sure the sources are reporting, and diagnosing problems without waiting for a supplier.
You run the platform, not just the alerts
This programme is aimed at security administrators, systems engineers and operations staff who are responsible for the platform itself: its availability, its capacity, its sources and its retention.
By the end you should be able to install a collector, onboard a new source, understand why an index is filling up and restore an interrupted feed without outside help. Everything is practised on a dedicated lab, where a mistake carries no consequences.
Linux or Windows system administration, a working understanding of networking and logging. No prior SIEM knowledge is required.
Skills covered
- Describe the platform architecture and the role of each component
- Install and configure agents and collectors
- Onboard a source and validate its normalisation
- Size indexes and manage retention
- Manage access, roles and service accounts
- Back up and restore the configuration
- Diagnose a loss of collection and fix it
- Track licence consumption
Five modules
| Module | Content | Format |
|---|---|---|
| 1 · Architecture | Platform components, data flows, standalone and distributed deployment models, sizing. | Lecture and case study |
| 2 · Installation | Setting up the components, initial configuration, securing access, certificates. | Hands-on |
| 3 · Data sources | Agents, collectors, formats, field extraction, normalisation to a common schema. | Hands-on |
| 4 · Operations | Indexes, retention, capacity planning, backup and restore, licence management. | Hands-on |
| 5 · Diagnosis | Silent sources, parsing drift, saturation, reading internal logs, investigation method. | Problem-solving workshops |
Organisation
| Duration | 4 to 5 days, depending on the platform and the group’s starting level |
| Audience | Security administrators, systems engineers, operations staff |
| Group size | 4 to 8 participants, to guarantee access to the exercises |
| Environment | A dedicated lab platform, separate from any production environment |
| Platforms covered | Splunk, Microsoft Sentinel, Elastic Security, OpenText ArcSight, Wazuh |
| Format | On site, remotely in a virtual classroom, or a mix of both |
| Follow-up | Course material kept by participants and a remote consolidation session included |
Let us build your session
Tell us which platform you operate and where your teams stand. We adapt the syllabus and send you a quotation.