Course : Log collection and analysis, a SIEM to optimize your IS security

Practical course - 3d - 21h00 - Ref. LCA
Price : 2470 CHF E.T.

Log collection and analysis, a SIEM to optimize your IS security




This training course will give you an overview of supervision issues, the legal obligations involved in data retention, and enable you to quickly master the skills needed to implement a software solution tailored to your needs.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Disponible en anglais, à la demande

Ref. LCA
  3d - 21h00
2470 CHF E.T.




This training course will give you an overview of supervision issues, the legal obligations involved in data retention, and enable you to quickly master the skills needed to implement a software solution tailored to your needs.


Teaching objectives
At the end of the training, the participant will be able to:
Know your legal obligations regarding data retention
Log analysis approach
Installing and configuring Syslog
Understanding correlation and analysis with SEC

Intended audience
System and network administrators.

Prerequisites
Good knowledge of networks, systems and IS security.

Practical details
Numerous exercises and case studies will be proposed throughout the course.

Course schedule

1
Information gathering

  • Heterogeneous sources. What is a safety event?
  • Security Information and Event Management (SIEM). Events collected from the IS.
  • Equipment system logs (firewalls, routers, servers, databases, etc.).
  • Passive collection in listening mode and active collection.
Hands-on work
Log analysis procedure. Geolocating an address. Correlating logs from different sources, visualizing, sorting and searching for rules.

2
Optimizing IS security: tools, best practices, pitfalls to avoid

  • Overview of solutions and products.
  • Syslog study.
  • The SEC.
  • Splunk software.
  • French legislation.
Hands-on work
Installation and configuration of Syslog, SEC, Splunk, ELK and more. Example of data analysis and correlation.

3
Intrusion detection, the main issues

  • Understand network protocols (TCP, UDP, ARP, ICMP, routers, firewalls, proxies, etc.).
  • Attacks on TCP/IP (spoofing, denial of service, session theft, SNMP attacks, etc.).
  • Intelligence gathering, trace search, network scans.
  • Detect trojans, backdoors, browser bug exploits, covert channels, distributed denial-of-service agents...
  • Attacks and exploitation of vulnerabilities (takeover, DDoS, buffer overflow, rootkits, etc.).


Customer reviews
4,6 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
ANNABEL C.
11/03/26
4 / 5

Not quite at my level, but very interesting. A practical exercise to try again at my own pace once I’ve gained more experience and, above all, improved my technique.
ARNAUD P.
11/03/26
4 / 5

A very comprehensive course; I would have liked a bit more time spent on syslog (both practical sessions and lectures). A good trainer who listened to the participants.
RENAUD L.
19/01/26
5 / 5

The content is very comprehensive and the trainer is an extremely competent teacher.



Publication date : 07/24/2025



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations

Dernières places
Date garantie en présentiel ou à distance
Session garantie
From 5 to 7 October 2026
FR
Remote class
Registration
From 16 to 18 November 2026
FR
Remote class
Registration
From 12 to 14 April 2027
FR
Remote class
Registration
From 12 to 14 April 2027
EN
Remote class
Registration
From 21 to 23 June 2027
FR
Remote class
Registration
From 21 to 23 June 2027
EN
Remote class
Registration
From 6 to 8 December 2027
FR
Remote class
Registration
From 6 to 8 December 2027
EN
Remote class
Registration

REMOTE CLASS
2026 : 5 Oct., 16 Nov.

2027 : 12 Apr., 12 Apr., 21 June, 21 June, 6 Dec., 6 Dec.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.