<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35137" language="de" source="https://portal.flane.ch/swisscom/xml-course/opentext-casfetr" lastchanged="2025-07-29T12:18:36+02:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Configuring ArcSight SOAR for Effective Threat Response</title><productcode>CASFETR</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-CASFETR</fullproductcode><version>3.8</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure SOAR to receive alerts from ESM&lt;/li&gt;&lt;li&gt;Describe the SOAR workflow&lt;/li&gt;&lt;li&gt;Configure integrations&lt;/li&gt;&lt;li&gt;Configure filtering, classifying, consolidating&lt;/li&gt;&lt;li&gt;and dispatching rules&lt;/li&gt;&lt;li&gt;Create workflow playbooks&lt;/li&gt;&lt;li&gt;Review system status&lt;/li&gt;&lt;li&gt;Run, schedule, and export reports&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;This course assumes a familiarity working with ArcSight ESM but it is not required&lt;/p&gt;</essentials><audience>&lt;p&gt;Administrators and Content Engineers responsible for configuring ArcSight security content.&lt;/p&gt;</audience><contents>&lt;p&gt;&lt;strong&gt;Module 1: Introduction to ArcSight SOAR&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Challenges Faced by Organizations&lt;/li&gt;&lt;li&gt;What Is ArcSight SOAR?&lt;/li&gt;&lt;li&gt;ArcSight SOAR Features.&lt;/li&gt;&lt;li&gt;Deployment Overview of ArcSight SOAR.&lt;/li&gt;&lt;li&gt;Accessing ArcSight SOAR&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2: Setting Up SOAR to Receive Alerts&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Installing a Forwarding Connector on ESM&lt;/li&gt;&lt;li&gt;Configuring a Forwarding Connector User and Web User on ESM&lt;/li&gt;&lt;li&gt;Configuring a Pre-persistent Rule to Tag the Events Forwarded to SOAR&lt;/li&gt;&lt;li&gt;Adding an ESM Alert Source on SOAR&lt;/li&gt;&lt;li&gt;Adding an ESM Integration on SOAR&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 3: Understanding the SOAR Workflow&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Processing ESM Alerts with SOAR&lt;/li&gt;&lt;li&gt;Rule Name Filters&lt;/li&gt;&lt;li&gt;Classification&lt;/li&gt;&lt;li&gt;Consolidation&lt;/li&gt;&lt;li&gt;Dispatching Cases&lt;/li&gt;&lt;li&gt;Automating Case Handling by Using Playbooks&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4: SOAR Integrations Overview&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SOAR Integrations Capabilities&lt;/li&gt;&lt;li&gt;Use Cases Benefits&lt;/li&gt;&lt;li&gt;Integrating SOAR with MISP&lt;/li&gt;&lt;li&gt;Integrating SOAR with VirusTotal&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5: SOAR Users, Groups, SSO&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Creating User Groups in Fusion&lt;/li&gt;&lt;li&gt;Creating Users in Fusion&lt;/li&gt;&lt;li&gt;Importing Existing Users from ESM&lt;/li&gt;&lt;li&gt;User Roles and Assigning Permissions&lt;/li&gt;&lt;li&gt;ACLs in SOAR&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6: SOAR Case Management&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understanding the SOAR Cases User Interface&lt;/li&gt;&lt;li&gt;Viewing Case Details&lt;/li&gt;&lt;li&gt;Managing Cases in SOAR&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7: Filtering, Classifying, Consolidating, and Dispatching Cases&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Filtering Alerts for Case Creation&lt;/li&gt;&lt;li&gt;Classifying Cases on SOAR&lt;/li&gt;&lt;li&gt;Consolidating Alerts to Create Cases&lt;/li&gt;&lt;li&gt;Dispatching Cases&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8: Automating Responses with Workflow Playbooks&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What are Playbooks?&lt;/li&gt;&lt;li&gt;Working with Playbooks&lt;/li&gt;&lt;li&gt;Workflow Playbooks&lt;/li&gt;&lt;li&gt;Scheduled Playbooks&lt;/li&gt;&lt;li&gt;Managing Triggers&lt;/li&gt;&lt;li&gt;Handling Manual Processes Through Tasks&lt;/li&gt;&lt;li&gt;Out of The Box Workflows&lt;/li&gt;&lt;li&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 9: SOAR System Status&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Alerts&lt;/li&gt;&lt;li&gt;Action and Rollback Queues&lt;/li&gt;&lt;li&gt;Action History&lt;/li&gt;&lt;li&gt;Enrichment History&lt;/li&gt;&lt;li&gt;Process Queues&lt;/li&gt;&lt;li&gt;Troubleshooting&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 10: Monitoring Using SOAR Dashboards and Reports&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Reports in Fusion&lt;/li&gt;&lt;li&gt;ArcSight SOAR Standard Content Resources&lt;/li&gt;&lt;li&gt;Scheduling and Exporting Reports&lt;/li&gt;&lt;li&gt;Running SOAR Legacy Reports (Jasper Reports)&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:


- Configure SOAR to receive alerts from ESM
- Describe the SOAR workflow
- Configure integrations
- Configure filtering, classifying, consolidating
- and dispatching rules
- Create workflow playbooks
- Review system status
- Run, schedule, and export reports</objective_plain><essentials_plain>This course assumes a familiarity working with ArcSight ESM but it is not required</essentials_plain><audience_plain>Administrators and Content Engineers responsible for configuring ArcSight security content.</audience_plain><contents_plain>Module 1: Introduction to ArcSight SOAR



- Challenges Faced by Organizations
- What Is ArcSight SOAR?
- ArcSight SOAR Features.
- Deployment Overview of ArcSight SOAR.
- Accessing ArcSight SOAR
Module 2: Setting Up SOAR to Receive Alerts



- Installing a Forwarding Connector on ESM
- Configuring a Forwarding Connector User and Web User on ESM
- Configuring a Pre-persistent Rule to Tag the Events Forwarded to SOAR
- Adding an ESM Alert Source on SOAR
- Adding an ESM Integration on SOAR

Module 3: Understanding the SOAR Workflow


- Processing ESM Alerts with SOAR
- Rule Name Filters
- Classification
- Consolidation
- Dispatching Cases
- Automating Case Handling by Using Playbooks
Module 4: SOAR Integrations Overview



- SOAR Integrations Capabilities
- Use Cases Benefits
- Integrating SOAR with MISP
- Integrating SOAR with VirusTotal
Module 5: SOAR Users, Groups, SSO


- Creating User Groups in Fusion
- Creating Users in Fusion
- Importing Existing Users from ESM
- User Roles and Assigning Permissions
- ACLs in SOAR
Module 6: SOAR Case Management


- Understanding the SOAR Cases User Interface
- Viewing Case Details
- Managing Cases in SOAR
Module 7: Filtering, Classifying, Consolidating, and Dispatching Cases


- Filtering Alerts for Case Creation
- Classifying Cases on SOAR
- Consolidating Alerts to Create Cases
- Dispatching Cases
Module 8: Automating Responses with Workflow Playbooks


- What are Playbooks?
- Working with Playbooks
- Workflow Playbooks
- Scheduled Playbooks
- Managing Triggers
- Handling Manual Processes Through Tasks
- Out of The Box Workflows
- 
Module 9: SOAR System Status


- Alerts
- Action and Rollback Queues
- Action History
- Enrichment History
- Process Queues
- Troubleshooting
Module 10: Monitoring Using SOAR Dashboards and Reports


- Reports in Fusion
- ArcSight SOAR Standard Content Resources
- Scheduling and Exporting Reports
- Running SOAR Legacy Reports (Jasper Reports)</contents_plain><duration unit="d" days="3">3 Tage</duration><pricelist><price country="DE" currency="EUR">2400.00</price></pricelist><miles/></course>