SECURITY / A CONCEPT NOTE
SIEM
centralized logging and alerting for security events
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A Security Information and Event Management (SIEM) system ingests logs from every source — cloud trails, firewall flows, server syslogs, app audit logs — normalizes them, and runs real-time correlation rules. When a rule fires (e.g., 'same user logs in from 2 continents in 5 minutes'), an alert is created for the SOC team to investigate.
02 / FOLLOW THE MECHANISM
How a siem pipeline works
Log sources
stream logs via syslog, CloudWatch, S3 events, or API to the SIEM collector.
Collector
normalizes disparate formats (JSON, syslog key=value, Windows Event XML) into a common schema.
Detection engine
runs hundreds of rules in real-time — signature-based (known IoCs), behavioral (anomalous volume), and threat-intel enriched.
SOC analyst
triages alerts in a dashboard, pivots on IPs, users, and timestamps to determine if it's a real incident or a false positive.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
check Wazuh SIEM agent status
wazuh-control statussearch for AWS console logins in Splunk
splunk search 'index=aws sourcetype=cloudtrail eventName=ConsoleLogin'05 / CHECK YOURSELF
Could you explain SIEM to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityJWTcompact, self-contained tokens for passing identity and claims