Lorsque vous vous inscrivez à ce cours, vous êtes également inscrit(e) à cette Spécialisation.
Apprenez de nouveaux concepts auprès d'experts du secteur
Acquérez une compréhension de base d'un sujet ou d'un outil
Développez des compétences professionnelles avec des projets pratiques
Obtenez un certificat professionnel partageable
Il y a 4 modules dans ce cours
In this course, you will be provided with a conceptual overview of logs and their role in Intrusion Detection Systems (IDSs) and Security Information and Event Management tools (SIEMs). The course will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk and Google SecOps (Chronicle), respectively. You will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic. This course will conclude with an introduction to Splunk and Google SecOps (Chronicle) and will showcase some of their features, including common commands.
By the end of this course, you will be able to:
- Discuss the importance of logs during incident investigation
- Determine how to read and analyze logs during incident investigation
- Describe how common intrusion detection system (IDS) tools provide security value
- Interpret the basic syntax and components of signatures and logs in IDS and NIDS tools
- Describe how SIEM tools collect, normalize, and analyze log data
- Perform queries in SIEM tools to investigate an incident
In this module, you will be provided with a conceptual overview of logs and their role in Intrusion Detection Systems (IDSs) and Security Information and Event Management tools (SIEMs). The module will highlight the importance of logs, best practices for log collection and management, the variations of logs, and provide an overview of log file formats.
Inclus
3 vidéos2 lectures2 devoirs1 plugin
Afficher les informations sur le contenu du module
3 vidéos•Total 9 minutes
Introduction to network traffic and logs using IDs and SIEM tools•1 minute
The importance of logs •4 minutes
Variations of logs •4 minutes
2 lectures•Total 16 minutes
Best practices for log collection and management•8 minutes
Overview of log file formats•8 minutes
2 devoirs•Total 16 minutes
Test your knowledge: Overview of logs•8 minutes
Test your knowledge: Log components and formats•8 minutes
1 plugin•Total 10 minutes
Identify: Match log files to their file format•10 minutes
Overview of intrusion detection systems (IDS)
Module 2•2 heures à terminer
Détails du module
This module will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk and Google SecOps (Chronicle), respectively. Learners will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic.
Afficher les informations sur le contenu du module
4 vidéos•Total 14 minutes
Security monitoring with detection tools •4 minutes
Components of a detection signature •4 minutes
Examine signatures with Suricata•4 minutes
Examine Suricata logs•2 minutes
5 lectures•Total 32 minutes
Detection tools and techniques•8 minutes
Overview of Suricata•8 minutes
Resources for completing labs•4 minutes
Lab tips and troubleshooting steps•4 minutes
Exemplar: Explore signatures with Suricata•8 minutes
1 devoir•Total 8 minutes
Test your knowledge: Overview of intrusion detection systems (IDS) •8 minutes
2 éléments d'application•Total 40 minutes
Activity: Explore signatures and logs with Suricata•30 minutes
Optional exemplar: Explore signatures and logs with Suricata•10 minutes
Overview of security information event management (SIEM) tools
Module 3•1 heure à terminer
Détails du module
In this module, you will get an introduction to Splunk and Google SecOps (Chronicle). The module will describe log sources and log ingestion and provide information on search methods with SIEM tools.
Inclus
3 vidéos2 lectures1 devoir
Afficher les informations sur le contenu du module
3 vidéos•Total 10 minutes
Reexamine SIEM tools•2 minutes
Query for events with Splunk•4 minutes
Query for events with Google SecOps•4 minutes
2 lectures•Total 16 minutes
Log sources and log ingestion•8 minutes
Search methods with SIEM tools•8 minutes
1 devoir•Total 30 minutes
Test your knowledge: Overview of SIEM tools•30 minutes
Review: Network traffic and logs using IDs and SIEM tools
Module 4•1 heure à terminer
Détails du module
Review everything you’ve learned and take the final assessment.
Inclus
1 lecture1 devoir
Afficher les informations sur le contenu du module
1 lecture•Total 10 minutes
Wrap-up•10 minutes
1 devoir•Total 50 minutes
Course 7 challenge: Network traffic and logs using IDs and SIEM tools•50 minutes
Obtenez un certificat professionnel
Ajoutez ce titre à votre profil LinkedIn, à votre curriculum vitae ou à votre CV. Partagez-le sur les médias sociaux et dans votre évaluation des performances.
Grow with Google is an initiative that draws on Google's decades-long history of building products, platforms, and services that help people and businesses grow. We aim to help everyone – those who make up the workforce of today and the students who will drive the workforce of tomorrow – access the best of Google’s training and tools to grow their skills, careers, and businesses.
Pour quelles raisons les étudiants sur Coursera nous choisissent-ils pour leur carrière ?
Felipe M.
Étudiant(e) depuis 2018
’Pouvoir suivre des cours à mon rythme à été une expérience extraordinaire. Je peux apprendre chaque fois que mon emploi du temps me le permet et en fonction de mon humeur.’
Jennifer J.
Étudiant(e) depuis 2020
’J'ai directement appliqué les concepts et les compétences que j'ai appris de mes cours à un nouveau projet passionnant au travail.’
Larry W.
Étudiant(e) depuis 2021
’Lorsque j'ai besoin de cours sur des sujets que mon université ne propose pas, Coursera est l'un des meilleurs endroits où se rendre.’
Chaitanya A.
’Apprendre, ce n'est pas seulement s'améliorer dans son travail : c'est bien plus que cela. Coursera me permet d'apprendre sans limites.’
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.