/ApacheMetronWorkshop

Apache Metron Workshop Lab materials and instructions.

Primary LanguageShell

Apache Metron Workshop

Objectives

After this workshop you will be able to:

  1. Open and describe the purpose of the Metron UIs.
  2. Parse and normalize squid log format using a Grok parser.
  3. Enrich squid events with geocoding and field transformations.
  4. Triage squid events
  5. Profiler Basics
  6. User and Entity Behavior Analytics(UEBA) with User Authentication Events
  7. Exploring Event History - Dashboards and Run Books for Analysis, Threat Hunting and Investigations
  8. Applying DGA Detection Machine Learning Predictions to Squid logs

Required Metron Version

The labs are designed to work with Apache Metron 0.5.1 as packaged in Hortonworks Cyber Security Platform. For more information consult the HCP Release Notes