BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//swoogo.com//NONSGML kigkonsult.se iCalcreator 2.41.90//
CALSCALE:GREGORIAN
UID:36626634-3335-4539-b430-363735626332
BEGIN:VEVENT
UID:7ed159e0562d4d44080845da7245b7398b05899a@swoogo.com
DTSTAMP:20260411T090241Z
DESCRIPTION:Course Description \n\nCreating Advanced ESM Content for Securi
 ty Use Cases covers ArcSight security problem solving methodology\n\nwithi
 n the ESM context. In this course\, you will learn advanced techniques to 
 use ArcSight ESM content to find\,\n\ntrack and remediate security inciden
 ts specifically identified in the course use cases. During the training\, 
 you will\n\nlearn to:\n\n• Use variables and correlation activities\n\n• C
 ustomize report templates to use dynamic content\n\n• Customize notificati
 on templates to send the appropriate notification based upon specific attr
 ibutes of an\n\nevent\n\nAudience/Job Roles\n\nThis course is intended for
 :\n\n• Defining organization’s security objectives\n\n• Building ArcSight 
 ESM content to adhere to those objectives\n\nCourse Objectives\n\nUpon suc
 cessful completion of this course\, you should be able to:\n\n• In an ArcS
 ight ESM context\, define a Use Case\n\n• Use the Use Case worksheet from 
 an initial problem statement\, generate requirement statements and\n\nprio
 ritize objectives\n\n• Identify data sources and ESM resources required to
  fulfil the objectives of the use case\n\n• To fulfil use case requirement
 s\, create identified ESM content\n\n• Construct ArcSight Variables to pro
 vide advanced analysis of the event stream\n\n• Develop ArcSight Rules to 
 allow advanced correlation activities\n\n• Build event-based data monitors
  to provide real-time views of event traffic and anomalies\n\n• Implement 
 custom velocity macros for notification\n\n• Package formulated ESM conten
 ts for the Use Case into ArcSight Resource Bundle\n\nPrerequisites/Recomme
 nded Skills\n\nTo be successful in this course\, you should have the follo
 wing prerequisites or knowledge:\n\n• 12 months experience creating ArcSig
 ht ESM content (recommended)\n\n• Computer desktop\, browser\, and file sy
 stem navigation skills\n\n• Basic understanding of TCP/IP networking and d
 atabase concepts\n\n• Enterprise security experience [highly advantageous]
  Plus\, an understanding of:\n\n▪ Network device functions and capabilitie
 s\, such as routers\, switches\, etc.\n\n▪ Security device functions and c
 apabilities\, such as IDS/IPS\, firewalls\, etc.\n\n▪ TCP/IP networking\, 
 file system\, and database concepts\n\n▪ SOC Organizational structure and 
 workflow hierarchy\n\n▪ SIEM terminology\, such as asset\, threat\, vulner
 ability\, safeguard\, etc.\n\n \n\n \n\n \n\n \n\n \n\n 
DTSTART:20200907T070000Z
DTEND:20200911T150000Z
LAST-MODIFIED:20260411T090241Z
LOCATION:
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:ESM280-70 ArcSight Creating Advanced ESM Content for Security Use C
 ases
TRANSP:OPAQUE
X-ALT-DESC;FMTTYPE=text/html:<div>\n<p align='left'><span style='font-size:
 18px\;'>Course Description </span></p>\n\n<p align='left'><span style='fon
 t-family:Calibri\;'><span style='font-size:small\;'><span style='font-fami
 ly:Calibri\;'><span style='font-size:small\;'>Creating Advanced ESM Conten
 t for Security Use Cases covers ArcSight security problem solving methodol
 ogy</span></span></span></span></p>\n\n<p align='left'><span style='font-f
 amily:Calibri\;'><span style='font-family:Calibri\;'>within the ESM contex
 t. In this course\, you will learn advanced techniques to use ArcSight ESM
  content to find\,</span></span></p>\n\n<p align='left'><span style='font-
 family:Calibri\;'><span style='font-family:Calibri\;'>track and remediate 
 security incidents specifically identified in the course use cases. During
  the training\, you will</span></span></p>\n\n<p align='left'><span style=
 'font-family:Calibri\;'><span style='font-family:Calibri\;'>learn to:</spa
 n></span></p>\n\n<p align='left'><span style='font-family:ArialMT\;'>- </s
 pan><span style='font-family:Calibri\;'><span style='font-size:small\;'><s
 pan style='font-family:Calibri\;'><span style='font-size:small\;'>Use vari
 ables and correlation activities</span></span></span></span></p>\n\n<p ali
 gn='left'><span style='font-family:ArialMT\;'>- </span><span style='font-f
 amily:Calibri\;'><span style='font-size:small\;'><span style='font-family:
 Calibri\;'><span style='font-size:small\;'>Customize report templates to u
 se dynamic content</span></span></span></span></p>\n\n<p align='left'><spa
 n style='font-family:ArialMT\;'>- </span><span style='font-family:Calibri\
 ;'><span style='font-size:small\;'><span style='font-family:Calibri\;'><sp
 an style='font-size:small\;'>Customize notification templates to send the 
 appropriate notification based upon specific attributes of an</span></span
 ></span></span></p>\n\n<p align='left'><span style='font-family:Calibri\;'
 ><span style='font-size:small\;'><span style='font-family:Calibri\;'><span
  style='font-size:small\;'>event</span></span></span></span></p>\n\n<p ali
 gn='left'><span style='font-family:Calibri\;'><span style='font-size:x-lar
 ge\;'><span style='font-family:Calibri\;'><span style='font-size:x-large\;
 '>Audience/Job Roles</span></span></span></span></p>\n\n<p align='left'><s
 pan style='font-family:Calibri\;'><span style='font-size:small\;'><span st
 yle='font-family:Calibri\;'><span style='font-size:small\;'>This course is
  intended for:</span></span></span></span></p>\n\n<p align='left'><span st
 yle='font-family:ArialMT\;'>- </span><span style='font-family:Calibri\;'><
 span style='font-size:small\;'><span style='font-family:Calibri\;'><span s
 tyle='font-size:small\;'>Defining organization’s security objectives</span
 ></span></span></span></p>\n\n<p align='left'><span style='font-family:Ari
 alMT\;'>- </span><span style='font-family:Calibri\;'><span style='font-siz
 e:small\;'><span style='font-family:Calibri\;'><span style='font-size:smal
 l\;'>Building ArcSight ESM content to adhere to those objectives</span></s
 pan></span></span></p>\n\n<p align='left'><span style='font-family:Calibri
 \;'><span style='font-size:x-large\;'><span style='font-family:Calibri\;'>
 <span style='font-size:x-large\;'>Course Objectives</span></span></span></
 span></p>\n\n<p align='left'><span style='font-family:Calibri\;'><span sty
 le='font-size:small\;'><span style='font-family:Calibri\;'><span style='fo
 nt-size:small\;'>Upon successful completion of this course\, you should be
  able to:</span></span></span></span></p>\n\n<p align='left'><span style='
 font-family:ArialMT\;'>- </span><span style='font-family:Calibri\;'><span 
 style='font-size:small\;'><span style='font-family:Calibri\;'><span style=
 'font-size:small\;'>In an ArcSight ESM context\, define a Use Case</span><
 /span></span></span></p>\n\n<p align='left'><span style='font-family:Arial
 MT\;'>- </span><span style='font-family:Calibri\;'><span style='font-size:
 small\;'><span style='font-family:Calibri\;'><span style='font-size:small\
 ;'>Use the Use Case worksheet from an initial problem statement\, generate
  requirement statements and</span></span></span></span></p>\n\n<p><span st
 yle='font-family:Calibri\;'><span style='font-size:small\;'><span style='f
 ont-family:Calibri\;'><span style='font-size:small\;'>prioritize objective
 s</span></span></span></span></p>\n\n<p align='left'><span style='font-fam
 ily:ArialMT\;'>- </span><span style='font-family:Calibri\;'><span style='f
 ont-size:small\;'><span style='font-family:Calibri\;'><span style='font-si
 ze:small\;'>Identify data sources and ESM resources required to fulfil the
  objectives of the use case</span></span></span></span></p>\n\n<p align='l
 eft'><span style='font-family:ArialMT\;'>- </span><span style='font-family
 :Calibri\;'><span style='font-size:small\;'><span style='font-family:Calib
 ri\;'><span style='font-size:small\;'>To fulfil use case requirements\, cr
 eate identified ESM content</span></span></span></span></p>\n\n<p align='l
 eft'><span style='font-family:ArialMT\;'>- </span><span style='font-family
 :Calibri\;'><span style='font-size:small\;'><span style='font-family:Calib
 ri\;'><span style='font-size:small\;'>Construct ArcSight Variables to prov
 ide advanced analysis of the event stream</span></span></span></span></p>
 \n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span sty
 le='font-family:Calibri\;'><span style='font-size:small\;'><span style='fo
 nt-family:Calibri\;'><span style='font-size:small\;'>Develop ArcSight Rule
 s to allow advanced correlation activities</span></span></span></span></p>
 \n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span sty
 le='font-family:Calibri\;'><span style='font-size:small\;'><span style='fo
 nt-family:Calibri\;'><span style='font-size:small\;'>Build event-based dat
 a monitors to provide real-time views of event traffic and anomalies</span
 ></span></span></span></p>\n\n<p align='left'><span style='font-family:Ari
 alMT\;'>- </span><span style='font-family:Calibri\;'><span style='font-siz
 e:small\;'><span style='font-family:Calibri\;'><span style='font-size:smal
 l\;'>Implement custom velocity macros for notification</span></span></span
 ></span></p>\n\n<p><span style='font-family:ArialMT\;'>- </span><span styl
 e='font-family:Calibri\;'><span style='font-size:small\;'><span style='fon
 t-family:Calibri\;'><span style='font-size:small\;'>Package formulated ESM
  contents for the Use Case into ArcSight Resource Bundle</span></span></sp
 an></span></p>\n\n<p align='left'><span style='font-family:Calibri\;'><spa
 n style='font-size:x-large\;'><span style='font-family:Calibri\;'><span st
 yle='font-size:x-large\;'>Prerequisites/Recommended Skills</span></span></
 span></span></p>\n\n<p align='left'><span style='font-family:Calibri\;'><s
 pan style='font-size:small\;'><span style='font-family:Calibri\;'><span st
 yle='font-size:small\;'>To be successful in this course\, you should have 
 the following prerequisites or knowledge:</span></span></span></span></p>
 \n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span sty
 le='font-family:Calibri\;'><span style='font-size:small\;'><span style='fo
 nt-family:Calibri\;'><span style='font-size:small\;'>12 months experience 
 creating ArcSight ESM content (recommended)</span></span></span></span></p
 >\n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span st
 yle='font-family:Calibri\;'><span style='font-size:small\;'><span style='f
 ont-family:Calibri\;'><span style='font-size:small\;'>Computer desktop\, b
 rowser\, and file system navigation skills</span></span></span></span></p>
 \n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span sty
 le='font-family:Calibri\;'><span style='font-size:small\;'><span style='fo
 nt-family:Calibri\;'><span style='font-size:small\;'>Basic understanding o
 f TCP/IP networking and database concepts</span></span></span></span></p>
 \n\n<p align='left'><span style='font-family:ArialMT\;'>- </span><span sty
 le='font-family:Calibri\;'><span style='font-size:small\;'><span style='fo
 nt-family:Calibri\;'><span style='font-size:small\;'>Enterprise security e
 xperience [highly advantageous] </span></span></span></span><span style='f
 ont-family:Arial\;'><span style='font-size:small\;'><span style='font-fami
 ly:Arial\;'><span style='font-size:small\;'>Plus\, an understanding of:</s
 pan></span></span></span></p>\n\n<p align='left'><font lang='ja' xml:lang=
 'ja'><span style='font-family:SegoeUISymbol\;'>▪ </span></font><span style
 ='font-family:Calibri\;'><span style='font-size:small\;'><span style='font
 -family:Calibri\;'><span style='font-size:small\;'>Network device function
 s and capabilities\, such as routers\, switches\, etc.</span></span></span
 ></span></p>\n\n<p align='left'><font lang='ja' xml:lang='ja'><span style=
 'font-family:SegoeUISymbol\;'>▪ </span></font><span style='font-family:Cal
 ibri\;'><span style='font-size:small\;'><span style='font-family:Calibri\;
 '><span style='font-size:small\;'>Security device functions and capabiliti
 es\, such as IDS/IPS\, firewalls\, etc.</span></span></span></span></p>\n
 \n<p align='left'><font lang='ja' xml:lang='ja'><span style='font-family:S
 egoeUISymbol\;'>▪ </span></font><span style='font-family:Calibri\;'><span 
 style='font-size:small\;'><span style='font-family:Calibri\;'><span style=
 'font-size:small\;'>TCP/IP networking\, file system\, and database concept
 s</span></span></span></span></p>\n\n<p align='left'><font lang='ja' xml:l
 ang='ja'><span style='font-family:SegoeUISymbol\;'>▪ </span></font><span s
 tyle='font-family:Calibri\;'><span style='font-size:small\;'><span style='
 font-family:Calibri\;'><span style='font-size:small\;'>SOC Organizational 
 structure and workflow hierarchy</span></span></span></span></p>\n\n<p><fo
 nt lang='ja' xml:lang='ja'><span style='font-family:SegoeUISymbol\;'>▪ </s
 pan></font><span style='font-family:Calibri\;'><span style='font-size:smal
 l\;'><span style='font-family:Calibri\;'><span style='font-size:small\;'>S
 IEM terminology\, such as asset\, threat\, vulnerability\, safeguard\, etc
 .</span></span></span></span></p>\n\n<p align='left'> </p>\n\n<p> </p>\n\n
 <p> </p>\n\n<p> </p>\n\n<p> </p>\n\n<p> </p>\n</div>
BEGIN:VALARM
UID:38313564-3266-4237-a333-633436616662
ACTION:DISPLAY
DESCRIPTION:Course Description \n\nCreating Advanced ESM Content for Securi
 ty Use Cases covers ArcSight security problem solving methodology\n\nwithi
 n the ESM context. In this course\, you will learn advanced techniques to 
 use ArcSight ESM content to find\,\n\ntrack and remediate security inciden
 ts specifically identified in the course use cases. During the training\, 
 you will\n\nlearn to:\n\n• Use variables and correlation activities\n\n• C
 ustomize report templates to use dynamic content\n\n• Customize notificati
 on templates to send the appropriate notification based upon specific attr
 ibutes of an\n\nevent\n\nAudience/Job Roles\n\nThis course is intended for
 :\n\n• Defining organization’s security objectives\n\n• Building ArcSight 
 ESM content to adhere to those objectives\n\nCourse Objectives\n\nUpon suc
 cessful completion of this course\, you should be able to:\n\n• In an ArcS
 ight ESM context\, define a Use Case\n\n• Use the Use Case worksheet from 
 an initial problem statement\, generate requirement statements and\n\nprio
 ritize objectives\n\n• Identify data sources and ESM resources required to
  fulfil the objectives of the use case\n\n• To fulfil use case requirement
 s\, create identified ESM content\n\n• Construct ArcSight Variables to pro
 vide advanced analysis of the event stream\n\n• Develop ArcSight Rules to 
 allow advanced correlation activities\n\n• Build event-based data monitors
  to provide real-time views of event traffic and anomalies\n\n• Implement 
 custom velocity macros for notification\n\n• Package formulated ESM conten
 ts for the Use Case into ArcSight Resource Bundle\n\nPrerequisites/Recomme
 nded Skills\n\nTo be successful in this course\, you should have the follo
 wing prerequisites or knowledge:\n\n• 12 months experience creating ArcSig
 ht ESM content (recommended)\n\n• Computer desktop\, browser\, and file sy
 stem navigation skills\n\n• Basic understanding of TCP/IP networking and d
 atabase concepts\n\n• Enterprise security experience [highly advantageous]
  Plus\, an understanding of:\n\n▪ Network device functions and capabilitie
 s\, such as routers\, switches\, etc.\n\n▪ Security device functions and c
 apabilities\, such as IDS/IPS\, firewalls\, etc.\n\n▪ TCP/IP networking\, 
 file system\, and database concepts\n\n▪ SOC Organizational structure and 
 workflow hierarchy\n\n▪ SIEM terminology\, such as asset\, threat\, vulner
 ability\, safeguard\, etc.\n\n \n\n \n\n \n\n \n\n \n\n 
TRIGGER:-PT30M
END:VALARM
END:VEVENT
END:VCALENDAR
