<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35144" language="de" source="https://portal.flane.ch/swisscom/xml-course/opentext-aseaa" lastchanged="2025-04-30T12:04:42+02:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>ArcSight ESM Advanced Administrator</title><productcode>ASEAA</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-ASEAA</fullproductcode><version>1.0</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify the ESM communication strategy used between the various devices and components within an ESM Network&lt;/li&gt;&lt;li&gt;Define each ESM operation modes and components, Compact and Distributed, and the issues ESM Distributed Mode comes to solve&lt;/li&gt;&lt;li&gt;Plan, install, and run ESM in Distributed Mode&lt;/li&gt;&lt;li&gt;Identify functions and navigate the Command Center UI&lt;/li&gt;&lt;li&gt;Install and customize the ESM console&lt;/li&gt;&lt;li&gt;Install and configure ArcSight SmartConnectors&lt;/li&gt;&lt;li&gt;Install and configure a Forwarding Connector&lt;/li&gt;&lt;li&gt;Import Zone and Asset information with the Network Model wizard&lt;/li&gt;&lt;li&gt;Customize ArcSight ESM using the properties files&lt;/li&gt;&lt;li&gt;Describe and install ArcSight upgrades and patches&lt;/li&gt;&lt;li&gt;Configure and manage storage groups&lt;/li&gt;&lt;li&gt;Describe CORRE daily job archives&lt;/li&gt;&lt;li&gt;Recognize how to Back up and restore ESM&lt;/li&gt;&lt;li&gt;Describe and deploy uses of SSL technology in ArcSight ESM&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Knowledge of ESM Concepts&lt;/li&gt;&lt;li&gt;(Minimum) 6 Months ArcSight Administration Experience&lt;/li&gt;&lt;li&gt;Database SQL statements experience&lt;/li&gt;&lt;li&gt;Linux Administration experience&lt;/li&gt;&lt;li&gt;Successful Completion of ArcSight ESM Administrator &amp;amp; Analyst Course or Equivalent Experience&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is intended for Administrators who:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Install, maintain, and troubleshoot ESM components&lt;/li&gt;&lt;li&gt;Design and implement integrations between ArcSight ESM and other ArcSight products&lt;/li&gt;&lt;li&gt;Proactively investigate the health of the ESM CORRE environment&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;p&gt;&lt;strong&gt;Module 1: Introduction to ESM Components&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe each ESM system component&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2: ESM Distributed Components&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Recognize where ESM fits within the ArcSight Architecture&lt;/li&gt;&lt;li&gt;Define each ESM operation modes, Compact and Distributed, and the issues ESM Distributed Mode comes to solve&lt;/li&gt;&lt;li&gt;Describe the ESM Distributed Mode components&lt;/li&gt;&lt;li&gt;Recognize the ArcSight Data Platform (ADP) and its components&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3: Installing ESM Distributed Mode&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Plan System Hardware Requirements&lt;/li&gt;&lt;li&gt;Check Operating System Pre-Installation&lt;/li&gt;&lt;li&gt;Install ESM Persistor Node&lt;/li&gt;&lt;li&gt;Install ESM Correlator Aggregator Node&lt;/li&gt;&lt;li&gt;Configure Integration of the Persistor Node&lt;/li&gt;&lt;li&gt;Add Correlator Aggregator Services&lt;/li&gt;&lt;li&gt;Configure Message Bus Data and Control Instances from Persistor&lt;/li&gt;&lt;li&gt;Configure Repository Instances from Persistor&lt;/li&gt;&lt;li&gt;Configure Distributed Cache on Correlator Aggregators&lt;/li&gt;&lt;li&gt;Run Cert Admin Approveall&lt;/li&gt;&lt;li&gt;Start All Cluster Wide Services from Persistor Node&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4: Maintaining ESM Properties Files and Upgrades&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Customize ArcSight ESM using Properties File&lt;/li&gt;&lt;li&gt;Prepare System for an Upgrade&lt;/li&gt;&lt;li&gt;Upgrade ESM&lt;/li&gt;&lt;li&gt;Upgrade the ESM Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5: Installing the ESM Console&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Install the ESM Console&lt;/li&gt;&lt;li&gt;Customize the ESM Console&lt;/li&gt;&lt;li&gt;Describe Tools available in the ESM Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6: Installing SmartConnectors&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe how Connectors collect, normalize, and cache events&lt;/li&gt;&lt;li&gt;Install and configure ArcSight SmartConnectors&lt;/li&gt;&lt;li&gt;Identify Connector Command Scripts&lt;/li&gt;&lt;li&gt;Describe how Connectors can be managed from an ESM Console, a Connector Appliance, or ArcSight Management Center&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7: Managing the Network Model&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List Network Model resources&lt;/li&gt;&lt;li&gt;Describe Asset Model resources&lt;/li&gt;&lt;li&gt;Add the following modelling resources:&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;Assets&lt;/li&gt;&lt;li&gt;Asset Ranges&lt;/li&gt;&lt;li&gt;Zones&lt;/li&gt;&lt;li&gt;Network and attach it to a connector&lt;/li&gt;&lt;li&gt;Import Zone and Asset information with the Network Model wizard&lt;/li&gt;&lt;li&gt;Explain the use of the Asset Import Connector&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8: Configuring SmartConnector Destinations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Get SmartConnector Status&lt;/li&gt;&lt;li&gt;Set SmartConnector Flow-Control&lt;/li&gt;&lt;li&gt;Use SmartConnector Administrative Dashboards&lt;/li&gt;&lt;li&gt;Configure SmartConnectors for Failover and Dual Destinations&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9: Installing the ESM Super and Syslog Connectors&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Install and configure a Forwarding Connector&lt;/li&gt;&lt;li&gt;Install and configure a Syslog connector&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10: SmartConnectors Configurations and Advanced Features&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure SmartConnectors using advanced features such as turbo mode, map files, event filtering, network options and event aggregation&lt;/li&gt;&lt;li&gt;Construct advanced configuration settings for optimal performance and data enrichment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 11: Command Center&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Log onto the ArcSight Command Center&lt;/li&gt;&lt;li&gt;Identify functions and navigate the User Interface&lt;/li&gt;&lt;li&gt;Use the ArcSight Command Center Help Facility&lt;/li&gt;&lt;li&gt;Configure:&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;Authentication&lt;/li&gt;&lt;li&gt;Content&lt;/li&gt;&lt;li&gt;Storage&lt;/li&gt;&lt;li&gt;Appliances&lt;/li&gt;&lt;li&gt;Identify stock content dashboards&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 12: ESM Backup and Restore&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Restore the ESM Manager&amp;#039;s configurations&lt;/li&gt;&lt;li&gt;Back up and restore ESM&lt;/li&gt;&lt;li&gt;Describe CORR-E Daily Job Archiving&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 13: Certificate Management&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe uses of SSL technology in ArcSight ESM&lt;/li&gt;&lt;li&gt;Describe SSL setup options&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;keytool/keytoolgui&lt;/li&gt;&lt;li&gt;certadmin&lt;/li&gt;&lt;li&gt;Identify the steps to deploy:&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;Self-signed Certificates&lt;/li&gt;&lt;li&gt;Approve/revoke distributed mode Certificates&lt;/li&gt;&lt;li&gt;CA (Certificate Authority)-signed Certificates&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:


- Identify the ESM communication strategy used between the various devices and components within an ESM Network
- Define each ESM operation modes and components, Compact and Distributed, and the issues ESM Distributed Mode comes to solve
- Plan, install, and run ESM in Distributed Mode
- Identify functions and navigate the Command Center UI
- Install and customize the ESM console
- Install and configure ArcSight SmartConnectors
- Install and configure a Forwarding Connector
- Import Zone and Asset information with the Network Model wizard
- Customize ArcSight ESM using the properties files
- Describe and install ArcSight upgrades and patches
- Configure and manage storage groups
- Describe CORRE daily job archives
- Recognize how to Back up and restore ESM
- Describe and deploy uses of SSL technology in ArcSight ESM</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:



- Knowledge of ESM Concepts
- (Minimum) 6 Months ArcSight Administration Experience
- Database SQL statements experience
- Linux Administration experience
- Successful Completion of ArcSight ESM Administrator &amp; Analyst Course or Equivalent Experience</essentials_plain><audience_plain>This course is intended for Administrators who:



- Install, maintain, and troubleshoot ESM components
- Design and implement integrations between ArcSight ESM and other ArcSight products
- Proactively investigate the health of the ESM CORRE environment</audience_plain><contents_plain>Module 1: Introduction to ESM Components


- Describe each ESM system component
Module 2: ESM Distributed Components


- Recognize where ESM fits within the ArcSight Architecture
- Define each ESM operation modes, Compact and Distributed, and the issues ESM Distributed Mode comes to solve
- Describe the ESM Distributed Mode components
- Recognize the ArcSight Data Platform (ADP) and its components
Module 3: Installing ESM Distributed Mode


- Plan System Hardware Requirements
- Check Operating System Pre-Installation
- Install ESM Persistor Node
- Install ESM Correlator Aggregator Node
- Configure Integration of the Persistor Node
- Add Correlator Aggregator Services
- Configure Message Bus Data and Control Instances from Persistor
- Configure Repository Instances from Persistor
- Configure Distributed Cache on Correlator Aggregators
- Run Cert Admin Approveall
- Start All Cluster Wide Services from Persistor Node
Module 4: Maintaining ESM Properties Files and Upgrades


- Customize ArcSight ESM using Properties File
- Prepare System for an Upgrade
- Upgrade ESM
- Upgrade the ESM Console
Module 5: Installing the ESM Console


- Install the ESM Console
- Customize the ESM Console
- Describe Tools available in the ESM Console
Module 6: Installing SmartConnectors


- Describe how Connectors collect, normalize, and cache events
- Install and configure ArcSight SmartConnectors
- Identify Connector Command Scripts
- Describe how Connectors can be managed from an ESM Console, a Connector Appliance, or ArcSight Management Center
Module 7: Managing the Network Model


- List Network Model resources
- Describe Asset Model resources
- Add the following modelling resources:

- Assets
- Asset Ranges
- Zones
- Network and attach it to a connector
- Import Zone and Asset information with the Network Model wizard
- Explain the use of the Asset Import Connector
Module 8: Configuring SmartConnector Destinations


- Get SmartConnector Status
- Set SmartConnector Flow-Control
- Use SmartConnector Administrative Dashboards
- Configure SmartConnectors for Failover and Dual Destinations
Module 9: Installing the ESM Super and Syslog Connectors


- Install and configure a Forwarding Connector
- Install and configure a Syslog connector
Module 10: SmartConnectors Configurations and Advanced Features


- Configure SmartConnectors using advanced features such as turbo mode, map files, event filtering, network options and event aggregation
- Construct advanced configuration settings for optimal performance and data enrichment
Module 11: Command Center


- Log onto the ArcSight Command Center
- Identify functions and navigate the User Interface
- Use the ArcSight Command Center Help Facility
- Configure:

- Authentication
- Content
- Storage
- Appliances
- Identify stock content dashboards
Module 12: ESM Backup and Restore


- Restore the ESM Manager's configurations
- Back up and restore ESM
- Describe CORR-E Daily Job Archiving
Module 13: Certificate Management


- Describe uses of SSL technology in ArcSight ESM
- Describe SSL setup options

- keytool/keytoolgui
- certadmin
- Identify the steps to deploy:

- Self-signed Certificates
- Approve/revoke distributed mode Certificates
- CA (Certificate Authority)-signed Certificates</contents_plain><duration unit="d" days="5">5 Tage</duration><pricelist><price country="DE" currency="EUR">4000.00</price></pricelist><miles/></course>