Overview

In this course, you will learn the fundamentals of using FortiAnalyzer for centralized logging and reporting. You will learn how to configure and deploy FortiAnalyzer, and identify threats and attack patterns through logging, analysis, and reporting. Finally, you will examine the management of events, incidents, playbooks, and some helpful troubleshooting techniques.

Skills Covered

After completing this course, you should be able to:

  • Describe key features and concepts of FortiAnalyzer
  • Deploy an appropriate architecture
  • Use administrative access controls
  • Monitor administrative events and tasks
  • Configure high availability
  • Understand HA synchronization and load balancing
  • Upgrade the firmware of an HA cluster
  • Verify the normal operation of an HA cluster
  • Manage ADOMs
  • Manage RAID
  • Register supported devices
  • Troubleshoot communication issues
  • Manage disk quota
  • Manage registered devices
  • Protect log information
  • View, search, manage, and troubleshoot logs
  • Monitor and manage events
  • Manage and customize event handlers
  • Create and manage incidents
  • Explore tools used for threat hunting
  • Create, run, and troubleshoot playbooks
  • Import and export playbooks
  • Generate and customize reports
  • Customize charts and datasets
  • Manage and troubleshoot reports

Who Should Attend

  • Anyone who is responsible for the day-to-day management of FortiAnalyzer devices and FortiGate security information.

Course Curriculum

Prerequisites

  • Familiarity with all topics presented in the NSE 4 FortiGate Security and NSE 4 FortiGate Infrastructure courses
  • Knowledge of SQL SELECT syntax is helpful, but not required

Download Syllabus

Course Modules

Request More Information

Training Options

Exam & Certification

This course prepares you for the FortiAnalyzer Specialist exam.
NSE 5 Network Security Analyst certification requires passing at least two NSE 5 Specialist exams.

Training & Certification Guide

Frequently Asked Questions