SIEM Platforms & Security Monitoring
This is where SOC work becomes hands-on. Students operate a real SIEM platform end to end — onboarding log sources, building dashboards, tuning correlation rules and investigating live offenses, the same workflow analysts run every shift.
What You Will Learn
A detailed, industry-aligned breakdown of every topic covered in this module.
- SIEM architecture, event & flow collectors
- IBM QRadar: dashboards & offense analysis
- Malicious IP communication & phishing analysis
- Windows, Linux & security device log types
- Correlation rules, false positives & alert triaging
- Reference sets, use-case creation & rule tuning
- Log source integration across the enterprise
- Generating governance & security reports
Tools You Will Use
Hands-on time with the same tools used in real Security Operations Centers today.
IBM QRadar
Enterprise SIEM platform used to build dashboards, correlate events and investigate security offenses.
Splunk
Log analysis and SIEM platform used to search, monitor and visualise machine data at scale.
Win Collect
Log collection agent used to forward Windows event logs into a SIEM platform.
Firewall Logs
Perimeter device logs used to detect blocked and suspicious network traffic patterns.
IPS / WAF
Intrusion prevention and web application firewall logs used to spot and block application-layer attacks.
Proxy Logs
Web proxy logs used to trace user and malware web activity across the network.
Hands-On Labs
Production-style SOC lab scenarios, built using the same stack real security teams monitor with.
Onboard log sources into IBM QRadar and configure event and flow collectors.
Build real-time SIEM dashboards and investigate offenses in QRadar.
Analyse malicious IP communication and phishing activity using live SIEM offense data.
Tune correlation rules and reference sets to reduce false positives.
Integrate log sources across the enterprise and generate governance and security reports.
Assessment
Knowledge Assessment
Quiz covering SIEM architecture, correlation rules, log source types and alert triaging.
Practical Evaluation
Students must build and tune a working SIEM dashboard with correlation rules, and investigate at least one offense end to end.
Projects
Industry-style deliverables added directly to your project portfolio.
SIEM Monitoring Lab
Onboard log sources into IBM QRadar, create reference sets and build real-time dashboards.
What This Module Builds
Students learn to operate a SIEM platform end to end — building dashboards, investigating offenses, tuning rules and producing real security reports.
