SIEM / Log analytics
SIEM / Log analytics
There are a number of ways to get experience of SIEM products both open source and 'free' trials of enterprise products.
Splunk
Splunk
Splunk is a very expensive enterprise product but they offer free trials both of their Cloud and on prem versions.
Note that this is the log analytics product, not the full Enterprise Security product, however you can install their 'Security Essentials' app.
https://www.splunk.com/en_us/download.html
They also offer free training
https://www.splunk.com/en_us/training/free-courses/overview.html
Microsoft Sentinel
Microsoft Sentinel
Lots of good training is available both listed here and below
Elasticsearch
Elasticsearch
The Elastic stack is free and open source
Qradar
Qradar
IBM's Qradar is pretty legacy as a SIEM but there are lots of deployments out there. They offer a 'free' Community Edition