Wenn Sie sich für diesen Kurs anmelden, werden Sie auch für diese Spezialisierung angemeldet.
Lernen Sie neue Konzepte von Branchenexperten
Gewinnen Sie ein Grundverständnis bestimmter Themen oder Tools
Erwerben Sie berufsrelevante Kompetenzen durch praktische Projekte
Erwerben Sie ein Berufszertifikat zur Vorlage
In diesem Kurs gibt es 4 Module
In this course, you will be provided with a conceptual overview of logs and their role in Intrusion Detection Systems (IDSs) and Security Information and Event Management tools (SIEMs). The course will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk and Google SecOps (Chronicle), respectively. You will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic. This course will conclude with an introduction to Splunk and Google SecOps (Chronicle) and will showcase some of their features, including common commands.
By the end of this course, you will be able to:
- Discuss the importance of logs during incident investigation
- Determine how to read and analyze logs during incident investigation
- Describe how common intrusion detection system (IDS) tools provide security value
- Interpret the basic syntax and components of signatures and logs in IDS and NIDS tools
- Describe how SIEM tools collect, normalize, and analyze log data
- Perform queries in SIEM tools to investigate an incident
In this module, you will be provided with a conceptual overview of logs and their role in Intrusion Detection Systems (IDSs) and Security Information and Event Management tools (SIEMs). The module will highlight the importance of logs, best practices for log collection and management, the variations of logs, and provide an overview of log file formats.
Das ist alles enthalten
3 Videos2 Lektüren2 Aufgaben1 Plug-in
Infos zu Modulinhalt anzeigen
3 Videos•Insgesamt 9 Minuten
Introduction to network traffic and logs using IDs and SIEM tools•1 Minute
The importance of logs •4 Minuten
Variations of logs •4 Minuten
2 Lektüren•Insgesamt 16 Minuten
Best practices for log collection and management•8 Minuten
Overview of log file formats•8 Minuten
2 Aufgaben•Insgesamt 16 Minuten
Test your knowledge: Overview of logs•8 Minuten
Test your knowledge: Log components and formats•8 Minuten
1 Plug-in•Insgesamt 10 Minuten
Identify: Match log files to their file format•10 Minuten
Overview of intrusion detection systems (IDS)
Modul 2•2 Stunden abzuschließen
Moduldetails
This module will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk and Google SecOps (Chronicle), respectively. Learners will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic.
Das ist alles enthalten
4 Videos5 Lektüren1 Aufgabe2 App-Elemente
Infos zu Modulinhalt anzeigen
4 Videos•Insgesamt 14 Minuten
Security monitoring with detection tools •4 Minuten
Components of a detection signature •4 Minuten
Examine signatures with Suricata•4 Minuten
Examine Suricata logs•2 Minuten
5 Lektüren•Insgesamt 32 Minuten
Detection tools and techniques•8 Minuten
Overview of Suricata•8 Minuten
Resources for completing labs•4 Minuten
Lab tips and troubleshooting steps•4 Minuten
Exemplar: Explore signatures with Suricata•8 Minuten
1 Aufgabe•Insgesamt 8 Minuten
Test your knowledge: Overview of intrusion detection systems (IDS) •8 Minuten
2 App-Elemente•Insgesamt 40 Minuten
Activity: Explore signatures and logs with Suricata•30 Minuten
Optional exemplar: Explore signatures and logs with Suricata•10 Minuten
Overview of security information event management (SIEM) tools
Modul 3•1 Stunde abzuschließen
Moduldetails
In this module, you will get an introduction to Splunk and Google SecOps (Chronicle). The module will describe log sources and log ingestion and provide information on search methods with SIEM tools.
Das ist alles enthalten
3 Videos2 Lektüren1 Aufgabe
Infos zu Modulinhalt anzeigen
3 Videos•Insgesamt 10 Minuten
Reexamine SIEM tools•2 Minuten
Query for events with Splunk•4 Minuten
Query for events with Google SecOps•4 Minuten
2 Lektüren•Insgesamt 16 Minuten
Log sources and log ingestion•8 Minuten
Search methods with SIEM tools•8 Minuten
1 Aufgabe•Insgesamt 30 Minuten
Test your knowledge: Overview of SIEM tools•30 Minuten
Review: Network traffic and logs using IDs and SIEM tools
Modul 4•1 Stunde abzuschließen
Moduldetails
Review everything you’ve learned and take the final assessment.
Das ist alles enthalten
1 Lektüre1 Aufgabe
Infos zu Modulinhalt anzeigen
1 Lektüre•Insgesamt 10 Minuten
Wrap-up•10 Minuten
1 Aufgabe•Insgesamt 50 Minuten
Course 7 challenge: Network traffic and logs using IDs and SIEM tools•50 Minuten
Erwerben Sie ein Karrierezertifikat.
Fügen Sie dieses Zeugnis Ihrem LinkedIn-Profil, Lebenslauf oder CV hinzu. Teilen Sie sie in Social Media und in Ihrer Leistungsbeurteilung.
Grow with Google is an initiative that draws on Google's decades-long history of building products, platforms, and services that help people and businesses grow. We aim to help everyone – those who make up the workforce of today and the students who will drive the workforce of tomorrow – access the best of Google’s training and tools to grow their skills, careers, and businesses.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.