Course Overview
Course Description
In this course, you learn to write and modify Collector plugins using the Sentinel SDK v2011.1r1 in an Eclipse environment and write new and modify existing reports found in Sentinel 7 and Sentinel Log Manager through both lecture and demonstrations.
Topics in this course include the following:
- What is SIEM?
- What is the SDK?
- Building a Simple Collector
- Directory and File Structure
- Parsing Logic
- Event Construction
- Taxonomy
- Reporting
- SDK Reporting and Branding
- iReport
- Data Queries
- Charting
- Chart Metrics
- Chart Colors
Course Prerequisites
This course requires a knowledge of scripting languages. Some programming experience is helpful, along with familiarity with Sentinel Eclipse.