Course Details
Course Outline
1 - Course Introduction
Introductions and course logisticsCourse objectives
2 - Architecture
Data flows and channelsSizing considerationsCommunication channels and ports
3 - Server Datastores
SOLR databaseStorage configurations and data agingPartition states PostgresModulestore
4 - EDR API
CBAPI overviewViewing API calls in the browserUtilizing the API to access data
5 - Threat Intelligence Feeds
Feed structureReport indicator typesCustom threat feed creation and addition
6 - Syslog Integration
SIEM supportConfiguration
7 - Troubleshooting
Server-side scriptsServer logsSensor operations
Actual course outline may vary depending on offering center. Contact your sales representative for more information.
Who is it For?
Target Audience
System administrators and security operations personnel, including analysts and managers
Prerequisites