Who should attend
Anyone who is responsible for the day-to-day management of FortiAnalyzer devices and FortiGate security information.
Prerequisites
- Familiarity with all topics presented in FortiGate Security (FORT-SECI) and FortiGate Infrastructure (FORT-INFRA) courses
- Knowledge of SQL SELECT syntax is helpful
System Requirements
-
If you take an online format of this class, you must use a computer that has the following:
- A high-speed internet connection
- An up-to-date web browser
- A PDF viewer
- Speakers/headphones
One of the following:
- HTML 5 support or
- An up-to-date Java Runtime Environment (JRE) with Java Plugin enabled in your web browser
You should use a wired Ethernet connection, not a WiFi connection. Firewalls, including Windows Firewall or FortiClient, must allow connections to the online labs.
Course Objectives
After completing this course, you will be able to:
- Describe key features and concepts of FortiAnalyzer
- Deploy an appropriate architecture
- Use administrative access controls
- Monitor administrative events and tasks
- Configure high availability
- Understand HA synchronization and load balancing
- Upgrade the firmware of an HA cluster
- Verify the normal operation of an HA cluster
- Manage ADOMs
- Configure RAID
- Register supported devices
- Troubleshoot communication issues
- Manage disk quota
- Manage registered devices
- Protect log information
- View, search, manage, and troubleshoot logs
- Monitor and manage events
- Manage and customize event handlers
- Create and manage incidents
- Explore tools used for threat hunting
- Create, run, and troubleshoot playbooks
- Import and export playbooks
- Generate and customize reports
- Customize charts and datasets
- Manage and troubleshoot reports
Course Content
In this course, you will learn the fundamentals of using FortiAnalyzer for centralized logging and reporting. You will learn how to configure and deploy FortiAnalyzer, and identify threats and attack patterns through logging, analysis, and reporting. Finally, you will examine the management of events, incidents, playbooks, and some helpful troubleshooting techniques.
This course is part of the preparation for the NSE 5 FortiAnalyzer certification exam.