<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35143" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/opentext-aseaaa" lastchanged="2025-07-29T12:18:36+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>ArcSight ESM Administrator and Analyst</title><productcode>ASEAAA</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-ASEAAA</fullproductcode><version>24.1</version><objective>&lt;p&gt;On completion of this course, participants should be able to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Make ArcSight ESM operational upon initial installation&lt;/li&gt;&lt;li&gt;Describe how ESM works in the context of your network&lt;/li&gt;&lt;li&gt;Create user accounts&lt;/li&gt;&lt;li&gt;Implement built-in content&lt;/li&gt;&lt;li&gt;Populate ESM with your network and assets to identify endpoints involved in an event&lt;/li&gt;&lt;li&gt;Create site-specific business-oriented views&lt;/li&gt;&lt;li&gt;Investigate, identify, analyze, and remediate exposed security issues&lt;/li&gt;&lt;li&gt;Use workflow management to provide real-time incident response and escalation tracking&lt;/li&gt;&lt;li&gt;Modify and run standard reports to provide situational awareness and network status&lt;/li&gt;&lt;li&gt;Establish ESM peering across multiple ESM instances&lt;/li&gt;&lt;li&gt;Perform distributed event search and content management&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;None&lt;/p&gt;</essentials><audience>&lt;p&gt;Analysts, Content Engineers, Business Administrators&lt;/p&gt;</audience><contents>&lt;p&gt;&lt;strong&gt;Module 1: ESM Overview&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discuss what ArcSight ESM is and how it fits into a SOC&lt;/li&gt;&lt;li&gt;List the problems ESM can solve&lt;/li&gt;&lt;li&gt;Discuss basic processes to make an ESM installation successful&lt;/li&gt;&lt;li&gt;Describe the basic ArcSight components (10&amp;#039; - 100,000&amp;#039; view)&lt;/li&gt;&lt;li&gt;Identify basic user roles within an ArcSight Installation&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2: Command Center&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discuss an overview of the Command Center&lt;/li&gt;&lt;li&gt;Describe how to use the Site Map&lt;/li&gt;&lt;li&gt;Describe how to monitor usage&lt;/li&gt;&lt;li&gt;Discuss how to configure Dashboards and the different Dashlets you can add&lt;/li&gt;&lt;li&gt;Describe how to use the Security Operations Center Dashboards&lt;/li&gt;&lt;li&gt;Explain how to configure and view MITRE Dashboards&lt;/li&gt;&lt;li&gt;Discuss how to monitor events with Active Channels&lt;/li&gt;&lt;li&gt;Discuss how to view and use Field Sets&lt;/li&gt;&lt;li&gt;Discuss how to view, export, and filter Active Lists&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3: ESM Console&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Install the ArcSight ESM Console&lt;/li&gt;&lt;li&gt;Start the ArcSight ESM Console&lt;/li&gt;&lt;li&gt;Use the Console Panels and Features&lt;/li&gt;&lt;li&gt;Customize the ESM console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4: Installing and Configuring ArcSight Connectors&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe a connector&lt;/li&gt;&lt;li&gt;Describe normalization&lt;/li&gt;&lt;li&gt;Describe a network model&lt;/li&gt;&lt;li&gt;Describe SmartConnectors&lt;/li&gt;&lt;li&gt;Deploy and configure SmartConnectors&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5: ArcSight Marketplace&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe what is the Marketplace&lt;/li&gt;&lt;li&gt;Define Marketplace packages/use cases&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6: Schema, Fieldsets, and Active Channels&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the ArcSight Event Schema&lt;/li&gt;&lt;li&gt;Describe an Active Channel&lt;/li&gt;&lt;li&gt;Describe what a field set is&lt;/li&gt;&lt;li&gt;Describe the Event Life Cycle&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7: Filters&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Filters and Filter Types&lt;/li&gt;&lt;li&gt;Create and Modify Filters&lt;/li&gt;&lt;li&gt;Debug Filters&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8: Dashboards &amp;amp; Data Monitors&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Data Monitor types and functions&lt;/li&gt;&lt;li&gt;Access and Use Dashboards&lt;/li&gt;&lt;li&gt;Modify Dashboard Data Monitor Layouts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9: Rules &amp;amp; Lists&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe rules and rule types&lt;/li&gt;&lt;li&gt;Describe rule triggers and actions&lt;/li&gt;&lt;li&gt;Describe Active Lists and Session Lists&lt;/li&gt;&lt;li&gt;Create and validate rule behavior&lt;/li&gt;&lt;li&gt;Create and validate Brute Force Login Attempt and Successful rules&lt;/li&gt;&lt;li&gt;Create and validate Active and Session List integration rules&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10: User Administration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create, edit, rename, delete user groups&lt;/li&gt;&lt;li&gt;Create, edit, move, delete users&lt;/li&gt;&lt;li&gt;Manage resource permissions&lt;/li&gt;&lt;li&gt;Access and modify global user password properties&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 11: Notifications&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the operation of ArcSight notifications&lt;/li&gt;&lt;li&gt;Configure ArcSight notifications&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 12: Incident Response and Automation with SOAR&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand SOAR&lt;/li&gt;&lt;li&gt;Triage cases with SOAR&lt;/li&gt;&lt;li&gt;Respond to Cases with Playbooks&lt;/li&gt;&lt;li&gt;Close a case&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 13: Queries and Query Viewers&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explain Queries&lt;/li&gt;&lt;li&gt;Define Query Viewers&lt;/li&gt;&lt;li&gt;Explain the advantages of using Query Viewers&lt;/li&gt;&lt;li&gt;Create the following functions with Query Viewers: Drilldowns, Baselines, Reports, Dashboard views&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 14: Reports&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define a report&lt;/li&gt;&lt;li&gt;Run, view, and save a report&lt;/li&gt;&lt;li&gt;Manage archived reports&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 15: Content Management and Peering&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Peer ESMs&lt;/li&gt;&lt;li&gt;Perform a search on a peer&lt;/li&gt;&lt;li&gt;Create a package and sync to a peer&lt;/li&gt;&lt;li&gt;Manually push a package&lt;/li&gt;&lt;li&gt;Verify successful distribution of a package&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 16: Event Search&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;how keyword, field-based and pipeline searches are performed&lt;/li&gt;&lt;li&gt;Describe how search results are displayed&lt;/li&gt;&lt;li&gt;Use the unified Search page to initiate any type of search&lt;/li&gt;&lt;li&gt;Use Search Helper and Search Builder features to save time constructing search expressions&lt;/li&gt;&lt;li&gt;Load, modify, and save search filters and saved searches&lt;/li&gt;&lt;li&gt;Enable peer ESM and Logger instances for searching&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:



- Make ArcSight ESM operational upon initial installation
- Describe how ESM works in the context of your network
- Create user accounts
- Implement built-in content
- Populate ESM with your network and assets to identify endpoints involved in an event
- Create site-specific business-oriented views
- Investigate, identify, analyze, and remediate exposed security issues
- Use workflow management to provide real-time incident response and escalation tracking
- Modify and run standard reports to provide situational awareness and network status
- Establish ESM peering across multiple ESM instances
- Perform distributed event search and content management</objective_plain><essentials_plain>None</essentials_plain><audience_plain>Analysts, Content Engineers, Business Administrators</audience_plain><contents_plain>Module 1: ESM Overview


- Discuss what ArcSight ESM is and how it fits into a SOC
- List the problems ESM can solve
- Discuss basic processes to make an ESM installation successful
- Describe the basic ArcSight components (10' - 100,000' view)
- Identify basic user roles within an ArcSight Installation
Module 2: Command Center


- Discuss an overview of the Command Center
- Describe how to use the Site Map
- Describe how to monitor usage
- Discuss how to configure Dashboards and the different Dashlets you can add
- Describe how to use the Security Operations Center Dashboards
- Explain how to configure and view MITRE Dashboards
- Discuss how to monitor events with Active Channels
- Discuss how to view and use Field Sets
- Discuss how to view, export, and filter Active Lists
Module 3: ESM Console


- Install the ArcSight ESM Console
- Start the ArcSight ESM Console
- Use the Console Panels and Features
- Customize the ESM console
Module 4: Installing and Configuring ArcSight Connectors


- Describe a connector
- Describe normalization
- Describe a network model
- Describe SmartConnectors
- Deploy and configure SmartConnectors
Module 5: ArcSight Marketplace


- Describe what is the Marketplace
- Define Marketplace packages/use cases
Module 6: Schema, Fieldsets, and Active Channels


- Describe the ArcSight Event Schema
- Describe an Active Channel
- Describe what a field set is
- Describe the Event Life Cycle
Module 7: Filters


- Describe Filters and Filter Types
- Create and Modify Filters
- Debug Filters
Module 8: Dashboards &amp; Data Monitors


- Identify Data Monitor types and functions
- Access and Use Dashboards
- Modify Dashboard Data Monitor Layouts
Module 9: Rules &amp; Lists


- Describe rules and rule types
- Describe rule triggers and actions
- Describe Active Lists and Session Lists
- Create and validate rule behavior
- Create and validate Brute Force Login Attempt and Successful rules
- Create and validate Active and Session List integration rules
Module 10: User Administration


- Create, edit, rename, delete user groups
- Create, edit, move, delete users
- Manage resource permissions
- Access and modify global user password properties
Module 11: Notifications


- Describe the operation of ArcSight notifications
- Configure ArcSight notifications
Module 12: Incident Response and Automation with SOAR


- Understand SOAR
- Triage cases with SOAR
- Respond to Cases with Playbooks
- Close a case
Module 13: Queries and Query Viewers


- Explain Queries
- Define Query Viewers
- Explain the advantages of using Query Viewers
- Create the following functions with Query Viewers: Drilldowns, Baselines, Reports, Dashboard views
Module 14: Reports


- Define a report
- Run, view, and save a report
- Manage archived reports
Module 15: Content Management and Peering


- Peer ESMs
- Perform a search on a peer
- Create a package and sync to a peer
- Manually push a package
- Verify successful distribution of a package
Module 16: Event Search


- how keyword, field-based and pipeline searches are performed
- Describe how search results are displayed
- Use the unified Search page to initiate any type of search
- Use Search Helper and Search Builder features to save time constructing search expressions
- Load, modify, and save search filters and saved searches
- Enable peer ESM and Logger instances for searching</contents_plain><duration unit="d" days="5">5 jours</duration><pricelist><price country="DE" currency="EUR">4000.00</price></pricelist><miles/></course>