Has been presented to
CERTIFICATE OF COMPLETION
Yechiel Worenklein
c1efd2db-1321-4114-9614-3afb5eeda0a6
Issue date
2024-09-23
On successful completion of
Google Security Operations SIEM Fundamentals
Certificate ID

Distributed by:

Issued to

Yechiel Worenklein

Want to report a typo or a mistake?

Credential Verification

Issue date: September 23, 2024

ID: c1efd2db-1321-4114-9614-3afb5eeda0a6

Fast Lane Israel logo

Issued by

VERIFIED

Fast Lane, the world's largest tech training company, specializes in technology and business training and consulting services. Partnering with major IT vendors like Microsoft, AWS, and Google, we support digital transformation worldwide.

Type

Course

Level

Foundational

Duration

3 days

Description

Explore the essentials of Chronicle, a powerful Security Information and Event Management (SIEM) solution offered as a cloud service on the robust Google infrastructure. The Chronicle Fundamentals course provides an in-depth overview of the key functionalities, data analysis capabilities, and security aspects of Chronicle SIEM.

Chronicle Access – Role-Based Access Control (RBAC) in Chronicle. Why Audit logging is important and how to implement it in your Chronicle instance.
Learn about Raw Log Search and UDM Search, how to use Search for investigation.
Chronicle Data On Boarding: forwarders, feed management, ingestion API, and direct ingestion.
Introduction to Chronicle Parsers – What is a parser, versioning, and parser extension.
Walkthrough of Chronicle Curated Detection rules.
Navigating Alerts using the Alert Graph: Entity data, releted alerts, alert context.
Learn about Entity data – Data enrichment in Chronicle, Entity types (Users & Assets), Resources, Geo IP Enrichment.
Advanced Search Capabilities: Reference Lists, Group Fields, Pivot, Search for Alerts.
Parsing data in Chronicle – What are parsers and how can we manage them: Parser update, versioning, parser extensions.
Building rules for Chronicle: YARA-L 2.0 syntax, Rules UI, Single event rules, Multi-event rules, using entity data in rules, Outcomes, Functions & Lists, best practice.
Building dashboards in Chronicle

Skills

Security Operations (SecOps)

Security Information And Event Management (SIEM)