<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="34394" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/training-csiemf" lastchanged="2025-10-20T09:26:48+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Chronicle SIEM Fundamentals</title><productcode>CSIEMF</productcode><vendorcode>FL</vendorcode><vendorname>Fast Lane</vendorname><fullproductcode>FL-CSIEMF</fullproductcode><version>1.0</version><objective>&lt;p&gt;Explore the essentials of Chronicle, a powerful Security Information and Event Management (SIEM) solution offered as a cloud service on the robust Google infrastructure. The Chronicle Fundamentals course provides an in-depth overview of the key functionalities, data analysis capabilities, and security aspects of Chronicle SIEM.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Chronicle Access &amp;ndash; Role-Based Access Control (RBAC) in Chronicle. Why Audit logging is important and how to implement it in your Chronicle instance.&lt;/li&gt;&lt;li&gt;Learn about Raw Log Search and UDM Search, how to use Search for investigation.&lt;/li&gt;&lt;li&gt;Chronicle Data On Boarding: forwarders, feed management, ingestion API, and direct ingestion.&lt;/li&gt;&lt;li&gt;Introduction to Chronicle Parsers &amp;ndash; What is a parser, versioning, and parser extension.&lt;/li&gt;&lt;li&gt;Walkthrough of Chronicle Curated Detection rules.&lt;/li&gt;&lt;li&gt;Navigating Alerts using the Alert Graph: Entity data, releted alerts, alert context.&lt;/li&gt;&lt;li&gt;Learn about Entity data &amp;ndash; Data enrichment in Chronicle, Entity types (Users &amp;amp; Assets), Resources, Geo IP Enrichment.&lt;/li&gt;&lt;li&gt;Advanced Search Capabilities: Reference Lists, Group Fields, Pivot, Search for Alerts.&lt;/li&gt;&lt;li&gt;Parsing data in Chronicle &amp;ndash; What are parsers and how can we manage them: Parser update, versioning, parser extensions.&lt;/li&gt;&lt;li&gt;Building rules for Chronicle: YARA-L 2.0 syntax, Rules UI, Single event rules, Multi-event rules, using entity data in rules, Outcomes, Functions &amp;amp; Lists, best practice.&lt;/li&gt;&lt;li&gt;Building dashboards in Chronicle.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;Basic knowledge about what is SIEM &amp;amp; SOAR&lt;/p&gt;</essentials><audience>&lt;p&gt;Individuals who need a basic introduction to Chronicle SIEM&lt;/p&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Module 1: Chronicle Access&lt;/li&gt;&lt;li&gt;Module 2: Searching with Chronicle&lt;br/&gt;Hands-On: Raw Log &amp;amp; UDM Search&lt;/li&gt;&lt;li&gt;Module 3: Chronicle Data On Boarding&lt;br/&gt;Hands-On: Collect Linux Syslog&lt;/li&gt;&lt;li&gt;Module 4: Parsing Data In Chronicle&lt;/li&gt;&lt;li&gt;Module 5: Curated Detections&lt;/li&gt;&lt;li&gt;Module 6: Visualizing Alerts With Chronicle&lt;br/&gt;Hands-On: Navigating and Reviewing using Alert Graph&lt;/li&gt;&lt;li&gt;Module 7: Entity Graph&lt;br/&gt;Hands-On: Search &amp;ndash; Asset\User Enrichment&lt;/li&gt;&lt;li&gt;Module 8: Advance Searching With Chronicle&lt;br/&gt;Hands-On: Advanced Search&lt;/li&gt;&lt;li&gt;Module 9: Building Rules For Chronicle&lt;br/&gt;Hands-On: Building Rules&lt;/li&gt;&lt;li&gt;Module 10: Visualizing Alerts (Advance)&lt;/li&gt;&lt;li&gt;Module 11: Entity Graph (Advance)&lt;/li&gt;&lt;li&gt;Module 12: Visualizing Data in Chronicle Hands-On: Building Dashboard In Chronicle&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>Explore the essentials of Chronicle, a powerful Security Information and Event Management (SIEM) solution offered as a cloud service on the robust Google infrastructure. The Chronicle Fundamentals course provides an in-depth overview of the key functionalities, data analysis capabilities, and security aspects of Chronicle SIEM.


- Chronicle Access – Role-Based Access Control (RBAC) in Chronicle. Why Audit logging is important and how to implement it in your Chronicle instance.
- Learn about Raw Log Search and UDM Search, how to use Search for investigation.
- Chronicle Data On Boarding: forwarders, feed management, ingestion API, and direct ingestion.
- Introduction to Chronicle Parsers – What is a parser, versioning, and parser extension.
- Walkthrough of Chronicle Curated Detection rules.
- Navigating Alerts using the Alert Graph: Entity data, releted alerts, alert context.
- Learn about Entity data – Data enrichment in Chronicle, Entity types (Users &amp; Assets), Resources, Geo IP Enrichment.
- Advanced Search Capabilities: Reference Lists, Group Fields, Pivot, Search for Alerts.
- Parsing data in Chronicle – What are parsers and how can we manage them: Parser update, versioning, parser extensions.
- Building rules for Chronicle: YARA-L 2.0 syntax, Rules UI, Single event rules, Multi-event rules, using entity data in rules, Outcomes, Functions &amp; Lists, best practice.
- Building dashboards in Chronicle.</objective_plain><essentials_plain>Basic knowledge about what is SIEM &amp; SOAR</essentials_plain><audience_plain>Individuals who need a basic introduction to Chronicle SIEM</audience_plain><contents_plain>- Module 1: Chronicle Access
- Module 2: Searching with Chronicle
Hands-On: Raw Log &amp; UDM Search
- Module 3: Chronicle Data On Boarding
Hands-On: Collect Linux Syslog
- Module 4: Parsing Data In Chronicle
- Module 5: Curated Detections
- Module 6: Visualizing Alerts With Chronicle
Hands-On: Navigating and Reviewing using Alert Graph
- Module 7: Entity Graph
Hands-On: Search – Asset\User Enrichment
- Module 8: Advance Searching With Chronicle
Hands-On: Advanced Search
- Module 9: Building Rules For Chronicle
Hands-On: Building Rules
- Module 10: Visualizing Alerts (Advance)
- Module 11: Entity Graph (Advance)
- Module 12: Visualizing Data in Chronicle Hands-On: Building Dashboard In Chronicle</contents_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="DE" currency="EUR">2995.00</price><price country="AT" currency="EUR">2995.00</price><price country="SE" currency="EUR">2995.00</price><price country="GB" currency="GBP">2595.00</price><price country="SI" currency="EUR">2995.00</price><price country="CH" currency="CHF">2995.00</price></pricelist><miles/></course>