IBM QRadar SIEM Administration and Offence Investigation Training Course
| Course code | SD-CS-061 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires more than monitoring dashboards: teams must onboard and validate log sources, maintain parsing and retention, tune correlation rules, investigate offences without losing evidential context, and distinguish genuine attack activity from routine operational noise. Poorly configured log sources, unprioritised offences and untuned rules can leave analysts chasing false positives while material threats remain buried in event data.
This five-day IBM QRadar SIEM Administration and Offence Investigation Training Course develops the operational skills needed to administer QRadar and investigate alerts efficiently. Participants configure core QRadar components; manage log sources, DSM parsing and event properties; create searches, saved criteria and dashboards; build custom rules, building blocks and reference data; and use offence magnitude, contributing events, flow data and asset context to triage incidents. The course also covers rule tuning, offence management, retention considerations, user roles, audit requirements and use-case alignment with MITRE ATT&CK techniques.
Instructor-led demonstrations are followed by guided work in a QRadar lab environment. Participants investigate realistic scenarios including credential misuse, suspicious network activity and anomalous endpoint events, documenting evidence, decisions and escalation actions. They leave with an offence investigation workbook containing search queries, triage notes, tuning recommendations, rule logic and an administration checklist that can be adapted for their own SOC or QRadar deployment.
The course is designed for practitioners who already work with security logs or monitoring platforms and now need reliable, hands-on control of IBM QRadar SIEM. It is equally relevant to managers seeking more consistent detection engineering, faster incident triage and measurable improvements in SIEM data quality.
Course objectives
By the end of this course, participants will be able to:
- Configure QRadar administrative settings, domains, user roles and access controls for a controlled SIEM operation
- Validate log source ingestion using DSM parsing, event properties and log source status indicators
- Construct AQL searches and saved search criteria to isolate suspicious events and investigation evidence
- Create custom correlation rules, building blocks and response actions for defined detection use cases
- Tune offence-generating rules by analysing false positives, thresholds, exceptions and rule dependencies
- Investigate QRadar offences using magnitude, contributing events, network flows, asset context and timeline evidence
- Manage reference data collections and custom properties to enrich correlation and investigation workflows
- Produce an offence investigation report and QRadar administration improvement plan for a realistic SOC scenario
Benefits of attending
For you
- Gain practical confidence administering QRadar log sources, rules, reference data and user access
- Build a repeatable method for moving from an offence to validated evidence and escalation decisions
- Develop AQL search and correlation-rule skills that support SOC analyst and detection engineering roles
- Create defensible investigation notes that demonstrate analytical judgement during incident reviews
- Strengthen credibility as a QRadar practitioner able to reduce false positives without weakening detection coverage
For your organisation
- Improve SIEM data quality by enabling staff to identify parsing failures, missing fields and unhealthy log sources
- Reduce analyst time spent on low-value alerts through rule tuning, building blocks and threshold refinement
- Standardise offence triage with documented searches, evidence requirements and escalation criteria
- Increase detection coverage by translating priority threats into QRadar rules aligned to MITRE ATT&CK techniques
- Create an actionable administration and tuning backlog based on issues identified during the course scenarios
Target competencies
Who should attend
- SOC Analysts — who investigate QRadar offences and need a repeatable evidence-led triage process
- IBM QRadar Administrators — who maintain log sources, rules, users, retention settings and platform health
- Security Engineers — who build detection use cases and integrate event sources into SIEM monitoring
- Incident Responders — who need to pivot from QRadar alerts into validated incident evidence and escalation decisions
- Threat Detection Engineers — who tune correlation logic and map detections to attacker techniques
- Cyber Security Team Leads — who need to improve offence quality, analyst consistency and SIEM operating procedures
Requirements and prerequisites
Participants should have practical familiarity with TCP/IP networking, common security events such as authentication failures and malware alerts, and basic Linux or command-line concepts. Experience reviewing logs in a SIEM, syslog collector or monitoring platform is strongly recommended. You should understand the purpose of firewalls, endpoints, identity services and network flows, although prior IBM QRadar administration experience is not required. Participants do not need programming expertise, data-science knowledge, prior certification or advanced digital forensics skills. The course introduces QRadar-specific navigation, AQL query construction and rule configuration from an intermediate operational baseline.
Training methodology
Each day combines instructor-led QRadar demonstrations with guided configuration tasks in a dedicated lab environment. Participants inspect raw events, validate DSM parsing, write AQL searches, configure correlation logic and investigate offences generated by realistic attack scenarios. Short case discussions examine why an alert should be closed, tuned, escalated or converted into a new detection use case. Working in pairs, participants document investigation evidence and tuning decisions. The final day concludes with an application-planning workshop that converts lab findings into priorities for their own QRadar environment.
Course outline
Day 1: QRadar architecture, navigation and data foundations
- QRadar SIEM architecture: Console, Event Processor, Flow Processor and data stores
- Admin, Log Activity, Network Activity, Offences and Assets workspace navigation
- Event, flow, asset and offence data models
- Log source types, protocols and collection methods
- DSM parsing, normalisation and low-level category mapping
- Log source status, event rate monitoring and ingestion troubleshooting
- User roles, security profiles, domains and administrative access control
Workshop: Participants validate a set of onboarded log sources, identify parsing or connectivity issues, and produce a log-source health checklist.
Day 2: Searching, dashboards and investigation context
- Log Activity search filters, time ranges and event grouping
- AQL query syntax for event fields, aggregations and filtering
- Saved searches, quick filters and search result management
- Network Activity analysis using flow records and communication patterns
- Asset profiles, vulnerability context and identity-related enrichment
- Custom event properties and extracted field validation
- Dashboard items, operational views and analyst monitoring panels
Workshop: Participants use AQL and flow analysis to investigate suspected credential abuse and produce an evidence timeline with key entities.
Day 3: Correlation rules and detection engineering
- Custom rule engine architecture and rule evaluation order
- Rule tests, responses, thresholds and time-window logic
- Building blocks for reusable inclusion and exclusion conditions
- Offence creation, contribution and magnitude calculation
- Reference sets, reference maps and reference map of sets
- Rule actions including notifications, annotations and response workflow
- MITRE ATT&CK mapping for QRadar detection use cases
Workshop: Participants build and test a correlation rule for suspicious authentication activity, using building blocks and a reference set to control scope.
Day 4: Offence investigation, triage and tuning
- Offence summary interpretation and prioritisation by magnitude
- Contributing events, contributing flows and related-offence analysis
- Investigation pivots across users, IP addresses, assets and event categories
- False-positive analysis using baselines, business context and expected behaviour
- Rule tuning through exceptions, threshold changes and building-block refinement
- Offence status management, assignments, notes and closure rationale
- Escalation criteria and evidence packages for incident response teams
Workshop: Participants triage a multi-stage offence, decide whether to escalate or tune it, and create a documented analyst case record.
Day 5: Operational administration and applied QRadar improvement
- Retention, storage allocation and event-data lifecycle considerations
- System notifications, audit logging and administrative monitoring
- Content management, rule export and controlled promotion practices
- QRadar Use Case Manager for use-case review and lifecycle tracking
- QRadar Log Source Management app for onboarding oversight
- Detection coverage gaps and prioritised tuning backlogs
- SOC operating procedures for daily QRadar administration and offence review
Workshop: Participants complete a capstone QRadar review, producing an administration checklist, tuning backlog and offence investigation report for a simulated SOC.
Tools & standards covered
IBM QRadar SIEM, IBM QRadar Use Case Manager, IBM QRadar Log Source Management app, MITRE ATT&CK
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Risk Oversight for Board Directors Training Course
Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …
Microsoft Sentinel Threat Detection Training Course
Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, inci…
MITRE ATT&CK Threat Detection Engineering Training Course
Security operations teams often collect more telemetry than they can investigate, yet still lack reliable detections for the techniques most…
OWASP Application Security Verification Standard Implementation Training Course
Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…