Festival Season Offer15% off on all our programmes — claim it before you enrol
MODULE 4 OF 5  ·  50 Hrs  ·  5 Weeks

SIEM Platforms & Security Monitoring

This is where SOC work becomes hands-on. Students operate a real SIEM platform end to end — onboarding log sources, building dashboards, tuning correlation rules and investigating live offenses, the same workflow analysts run every shift.

Who This Module Is For
Students who have completed the SOC-fundamentals module and are ready to operate a real SIEM platform.
Real-World Relevance
SIEM fluency — especially on IBM QRadar and Splunk — is the single most tested hands-on skill in SOC Analyst interviews, because it's the platform analysts live in every day.
Program OverviewView Hands-On Labs
Curriculum

What You Will Learn

A detailed, industry-aligned breakdown of every topic covered in this module.

  • SIEM architecture, event & flow collectors
  • IBM QRadar: dashboards & offense analysis
  • Malicious IP communication & phishing analysis
  • Windows, Linux & security device log types
  • Correlation rules, false positives & alert triaging
  • Reference sets, use-case creation & rule tuning
  • Log source integration across the enterprise
  • Generating governance & security reports
Technology Stack

Tools You Will Use

Hands-on time with the same tools used in real Security Operations Centers today.

IBM QRadar

Enterprise SIEM platform used to build dashboards, correlate events and investigate security offenses.

Splunk

Log analysis and SIEM platform used to search, monitor and visualise machine data at scale.

Win Collect

Log collection agent used to forward Windows event logs into a SIEM platform.

Firewall Logs

Perimeter device logs used to detect blocked and suspicious network traffic patterns.

IPS / WAF

Intrusion prevention and web application firewall logs used to spot and block application-layer attacks.

Proxy Logs

Web proxy logs used to trace user and malware web activity across the network.

Practical Work

Hands-On Labs

Production-style SOC lab scenarios, built using the same stack real security teams monitor with.

01

Onboard log sources into IBM QRadar and configure event and flow collectors.

02

Build real-time SIEM dashboards and investigate offenses in QRadar.

03

Analyse malicious IP communication and phishing activity using live SIEM offense data.

04

Tune correlation rules and reference sets to reduce false positives.

05

Integrate log sources across the enterprise and generate governance and security reports.

Evaluation

Assessment

Knowledge Assessment

Quiz covering SIEM architecture, correlation rules, log source types and alert triaging.

Practical Evaluation

Students must build and tune a working SIEM dashboard with correlation rules, and investigate at least one offense end to end.

Portfolio

Projects

Industry-style deliverables added directly to your project portfolio.

Portfolio Project 01

SIEM Monitoring Lab

Onboard log sources into IBM QRadar, create reference sets and build real-time dashboards.

Module Outcome

What This Module Builds

Students learn to operate a SIEM platform end to end — building dashboards, investigating offenses, tuning rules and producing real security reports.

Maps to job roles
SOC Analyst (L1/L2)SIEM / Security Engineer (Trainee)Security Monitoring AnalystLog Analysis Engineer

Continue building your SOC analyst portfolio

Next up: Module 5 — Incident Response & Threat Hunting

Go to Module 5Full Roadmap