You are on page 1of 2

Course Description

FortiSIEM

In this course, you will learn about FortiSIEM initial configurations, architecture,
and the discovery of devices on the network. You will also learn how to collect
performance information and aggregate it with syslog data to enrich the overall
view of the health of your environment, how to use the configuration database to
greatly facilitate compliance audits, and how to integrate FortiSIEM into your
network awareness infrastructure.

Product Version
FortiSIEM 6.3

Course Duration
l Lecture time (estimated): 11 hours
l Lab time (estimated): 9 hours
l Total course duration (estimated): 20 hours/3 days

Who Should Attend


Anyone who is responsible for the day-to-day management of FortiSIEM should attend this course.

Certification
This course is part of the preparation for the NSE 5 certification exam.

12/19/2021

https://training.fortinet.com
FortiSIEM 6.3 Course Description

l Understand agent registration


Prerequisites l Monitor agent communications after deployment
You must have an understanding of the topics covered l Troubleshoot FortiSIEM issues
in the following courses, or have equivalent experience.
l NSE 4 FortiGate Security Training Delivery Options and SKUs
l NSE 4 FortiGate Infrastructure
Instructor-Led Training

Includes standard NSE training content delivered in


Agenda person onsite, or live online using a virtual classroom
1. Introduction application. Training is delivered within public classes
or as a private class. Private requests are scoped,
2. SIEM and PAM Concepts
quoted, developed, and delivered by Fortinet Training
3. Discovery and FortiSIEM Agents (minimum quantities apply).
4. FortiSIEM Analytics
Use the following ILT Training SKU to purchase
5. CMDB Lookups and Filters
scheduled public classes of this course through
6. Group By and Data Aggregation Fortinet Resellers or Authorized Training Partners:
7. Rules and MITRE ATT&CK
FT-FSM
8. Incidents and Notification Policies
9. Reports and Dashboards Self-Paced Training
10. Maintaining and Tuning Includes online training videos and resources through
11. Troubleshooting the NSE Training Institute library, free of charge.

You can purchase on-demand lab access with


Objectives interactive, hands-on activities using a purchase order
(PO) through Fortinet Resellers or Authorized Training
After completing this course, you will be able to: Partners.
l Identify business drivers for using SIEM tools After you complete the purchase, you receive lab
l Describe SIEM and PAM concepts access and the accompanying lab guide within the self-
l Describe key features of FortiSIEM paced course.
l Understand how collectors, workers, and supervisors Use the following on-demand lab training SKU to
work together purchase lab access using a PO:
l Configure notifications
FT-FSM-LAB
l Create new users and custom roles
l Describe and enable devices for discovery See Purchasing Process for more information about
purchasing Fortinet training products.
l Understand when to use agents
l Perform real-time, historic structured searches
l Group and aggregate search results (ISC)2
l Examine performance metrics l CPE training hours: 11
l Create custom incident rules l CPE lab hours: 9
l Edit existing, or create new, reports l CISSP domains: Security Operations
l Configure and customize the dashboards
l Export CMDB information
Program Policies and FAQs
l Identify Windows agent components
l Describe the purpose of Windows agents For questions about courses, certification, or training
l Understand how the Windows agent manager works in products, refer to Program Policy Guidelines or
various deployment models Frequently Asked Questions.
l Identify reports that relate to Windows agents
l Understand the FortiSIEM Linux file monitoring agent

You might also like