<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.de/css/xml-course.xsl"?><course productid="33434" language="en" source="https://portal.flane.de/ibb/en/xml-course/opentext-esm320-76" lastchanged="2025-07-29T12:18:23+02:00" parent="https://portal.flane.de/ibb/en/xml-courses"><title>ArcSight-ESM-Advanced Analyst with Certified Expert Exam</title><productcode>ESM320-76</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-ESM320-76</fullproductcode><version>7.6</version><objective>&lt;p&gt;Upon successful completion of this course, you should be able to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Navigate ArcSight ESM console and command center to correlate, investigate, analyze and remediate both exposed and obscure threats&lt;/li&gt;&lt;li&gt;Construct ArcSight variables to provide advanced analysis of the event stream&lt;/li&gt;&lt;li&gt;Develop ArcSight lists and rules to allow advanced correlation activities&lt;/li&gt;&lt;li&gt;Optimize event-based data monitors to provide real-time viewing of event traffic and anomalies&lt;/li&gt;&lt;li&gt;Design new report templates and create functional reports&lt;/li&gt;&lt;li&gt;Find events through the search tools&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Common security devices such as IDS and firewalls&lt;/li&gt;&lt;li&gt;Common network device functions, such as routers, switches, and hubs&lt;/li&gt;&lt;li&gt;TCP/IP functions such as CIDR blocks, subnets, addressing, and communications&lt;/li&gt;&lt;li&gt;Basic Windows operating system tasks and functions&lt;/li&gt;&lt;li&gt;Possible attack activities, such as scans, man in the middle, sniffing, DoS, and possible abnormal activities, such as worms, Trojans, and viruses&lt;/li&gt;&lt;li&gt;SIEM terminology, such as threat, vulnerability, risk, asset, exposure, and safeguards&lt;/li&gt;&lt;li&gt;Completed the ArcSight ESM Administrator and Analyst course or 6 months experience administering ArcSight ESM&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is intended for analysts responsible for:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Defining their organization&amp;rsquo;s security objectives&lt;/li&gt;&lt;li&gt;Building or using advanced content to correlate, view and respond to those security objectives.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Module 1: ESM Overview&lt;/li&gt;&lt;li&gt;Module 2: Command Center&lt;/li&gt;&lt;li&gt;Module 3: ArcSight Console&lt;/li&gt;&lt;li&gt;Module 4: Active Channels&lt;/li&gt;&lt;li&gt;Module 5: Filters&lt;/li&gt;&lt;li&gt;Module 6: Variable Customization&lt;/li&gt;&lt;li&gt;Module 7: Data Monitors and Dashbords&lt;/li&gt;&lt;li&gt;Module 8: ESM Lists&lt;/li&gt;&lt;li&gt;Module 9: ESM Rules&lt;/li&gt;&lt;li&gt;Module 10: Query Viewers Authoring&lt;/li&gt;&lt;li&gt;Module 11: ESM Reports&lt;/li&gt;&lt;li&gt;Module 12: Unified Event Search Tools&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;p&gt;Module 1: ESM Overview
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify ESM Architecture&lt;/li&gt;&lt;li&gt;Describe the content of the ArcSight Event Schema&lt;/li&gt;&lt;li&gt;List the phases of the ArcSight Event Lifecycle&lt;/li&gt;&lt;li&gt;Describe the event processing and schema population performed during each phase of the event lifecycle&lt;/li&gt;&lt;li&gt;List the resources and tools applicable to specific phases of the event lifecycle&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 2: Command Center
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Access the ArcSight ESM Command Center&lt;/li&gt;&lt;li&gt;Monitor Usage Metrics&lt;/li&gt;&lt;li&gt;View System Metrics&lt;/li&gt;&lt;li&gt;Use the SOC/MITRE Dashboards&lt;/li&gt;&lt;li&gt;Access and use Active Lists&lt;/li&gt;&lt;li&gt;Utilize Field Sets&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 3: ArcSight Console
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Launch the ArcSight Console&lt;/li&gt;&lt;li&gt;Identify toolbar components and their functions&lt;/li&gt;&lt;li&gt;List the different views available in the Viewer panel&lt;/li&gt;&lt;li&gt;Identify three methods to access Console Help&lt;/li&gt;&lt;li&gt;Describe the Reference Resources and their characteristics&lt;/li&gt;&lt;li&gt;Identify ESM Console preference options&lt;/li&gt;&lt;li&gt;Customize your ESM Console&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 4: Active Channels
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a new Active Channel&lt;/li&gt;&lt;li&gt;View the details of an event&lt;/li&gt;&lt;li&gt;Identify Dynamic and Static Active Channels&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 5: Filters
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe Filter types and usage&lt;/li&gt;&lt;li&gt;Add, edit and save Filters to an Active Channel&lt;/li&gt;&lt;li&gt;Define the Common Conditions Editor&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 6: Variable Customization
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe functions available in Variables&lt;/li&gt;&lt;li&gt;Create both Local and Global Variables&lt;/li&gt;&lt;li&gt;Promote Local to Global Variables&lt;/li&gt;&lt;li&gt;Share Global Variables among multiple resources&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 7: Data Monitors and Dashbords
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify Data Monitor types and functions&lt;/li&gt;&lt;li&gt;Create a Data Monitor&lt;/li&gt;&lt;li&gt;Access and Use Dashboards&lt;/li&gt;&lt;li&gt;Modify Dashboard Data Monitor Layouts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 8: ESM Lists
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the differences between Active and Session Lists&lt;/li&gt;&lt;li&gt;Create and validate Active and Session List integration Rules&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 9: ESM Rules
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create and validate the following:&lt;/li&gt;&lt;li&gt;Rule behavior&lt;/li&gt;&lt;li&gt;Brute Force Login Attempt and Successful rules&lt;/li&gt;&lt;li&gt;Light Weight rules and Pre-Persistent rules&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 10: Query Viewers Authoring
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define Queries&lt;/li&gt;&lt;li&gt;Describe Query Viewers&lt;/li&gt;&lt;li&gt;Explain the advantages of using Query Viewers&lt;/li&gt;&lt;li&gt;Create the following functions with Query Viewers:&lt;/li&gt;&lt;li&gt;Drilldowns&lt;/li&gt;&lt;li&gt;Baselines&lt;/li&gt;&lt;li&gt;Reports&lt;/li&gt;&lt;li&gt;Dashboard views&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 11: ESM Reports
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;List the components in the Report Workflow&lt;/li&gt;&lt;li&gt;List the different types of Reports&lt;/li&gt;&lt;li&gt;Run a Report from the Navigator panel&lt;/li&gt;&lt;li&gt;View an Archive Report from the Navigator panel&lt;/li&gt;&lt;li&gt;Set up a scheduled Report job&lt;/li&gt;&lt;li&gt;Build a custom Report&lt;/li&gt;&lt;li&gt;Build a custom Trend Report&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Module 12: Unified Event Search Tools
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe how keyword, field-based and pipeline searches are performed&lt;/li&gt;&lt;li&gt;Describe how search results are displayed&lt;/li&gt;&lt;li&gt;Use the unified Search page to initiate any type of search&lt;/li&gt;&lt;li&gt;Use Search Helper and Search Builder features to save time constructing search expressions&lt;/li&gt;&lt;li&gt;Load, modify, and save search filters and saved searches&lt;/li&gt;&lt;li&gt;Enable peer ESM and Logger instances for searching&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>Upon successful completion of this course, you should be able to:



- Navigate ArcSight ESM console and command center to correlate, investigate, analyze and remediate both exposed and obscure threats
- Construct ArcSight variables to provide advanced analysis of the event stream
- Develop ArcSight lists and rules to allow advanced correlation activities
- Optimize event-based data monitors to provide real-time viewing of event traffic and anomalies
- Design new report templates and create functional reports
- Find events through the search tools</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:



- Common security devices such as IDS and firewalls
- Common network device functions, such as routers, switches, and hubs
- TCP/IP functions such as CIDR blocks, subnets, addressing, and communications
- Basic Windows operating system tasks and functions
- Possible attack activities, such as scans, man in the middle, sniffing, DoS, and possible abnormal activities, such as worms, Trojans, and viruses
- SIEM terminology, such as threat, vulnerability, risk, asset, exposure, and safeguards
- Completed the ArcSight ESM Administrator and Analyst course or 6 months experience administering ArcSight ESM</essentials_plain><audience_plain>This course is intended for analysts responsible for:



- Defining their organization’s security objectives
- Building or using advanced content to correlate, view and respond to those security objectives.

-</audience_plain><contents_plain>- Module 1: ESM Overview
- Module 2: Command Center
- Module 3: ArcSight Console
- Module 4: Active Channels
- Module 5: Filters
- Module 6: Variable Customization
- Module 7: Data Monitors and Dashbords
- Module 8: ESM Lists
- Module 9: ESM Rules
- Module 10: Query Viewers Authoring
- Module 11: ESM Reports
- Module 12: Unified Event Search Tools</contents_plain><outline_plain>Module 1: ESM Overview



- Identify ESM Architecture
- Describe the content of the ArcSight Event Schema
- List the phases of the ArcSight Event Lifecycle
- Describe the event processing and schema population performed during each phase of the event lifecycle
- List the resources and tools applicable to specific phases of the event lifecycle
Module 2: Command Center



- Access the ArcSight ESM Command Center
- Monitor Usage Metrics
- View System Metrics
- Use the SOC/MITRE Dashboards
- Access and use Active Lists
- Utilize Field Sets
Module 3: ArcSight Console



- Launch the ArcSight Console
- Identify toolbar components and their functions
- List the different views available in the Viewer panel
- Identify three methods to access Console Help
- Describe the Reference Resources and their characteristics
- Identify ESM Console preference options
- Customize your ESM Console
Module 4: Active Channels



- Create a new Active Channel
- View the details of an event
- Identify Dynamic and Static Active Channels
Module 5: Filters



- Describe Filter types and usage
- Add, edit and save Filters to an Active Channel
- Define the Common Conditions Editor
Module 6: Variable Customization



- Describe functions available in Variables
- Create both Local and Global Variables
- Promote Local to Global Variables
- Share Global Variables among multiple resources
Module 7: Data Monitors and Dashbords



- Identify Data Monitor types and functions
- Create a Data Monitor
- Access and Use Dashboards
- Modify Dashboard Data Monitor Layouts
Module 8: ESM Lists



- Describe the differences between Active and Session Lists
- Create and validate Active and Session List integration Rules
Module 9: ESM Rules



- Create and validate the following:
- Rule behavior
- Brute Force Login Attempt and Successful rules
- Light Weight rules and Pre-Persistent rules
Module 10: Query Viewers Authoring



- Define Queries
- Describe Query Viewers
- Explain the advantages of using Query Viewers
- Create the following functions with Query Viewers:
- Drilldowns
- Baselines
- Reports
- Dashboard views
Module 11: ESM Reports



- List the components in the Report Workflow
- List the different types of Reports
- Run a Report from the Navigator panel
- View an Archive Report from the Navigator panel
- Set up a scheduled Report job
- Build a custom Report
- Build a custom Trend Report
Module 12: Unified Event Search Tools



- Describe how keyword, field-based and pipeline searches are performed
- Describe how search results are displayed
- Use the unified Search page to initiate any type of search
- Use Search Helper and Search Builder features to save time constructing search expressions
- Load, modify, and save search filters and saved searches
- Enable peer ESM and Logger instances for searching</outline_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="FR" currency="EUR">3750.00</price><price country="DE" currency="EUR">4000.00</price></pricelist><miles/></course>