SECURITY / A CONCEPT NOTE

SIEM

centralized logging and alerting for security events

~75 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A Security Information and Event Management (SIEM) system ingests logs from every source — cloud trails, firewall flows, server syslogs, app audit logs — normalizes them, and runs real-time correlation rules. When a rule fires (e.g., 'same user logs in from 2 continents in 5 minutes'), an alert is created for the SOC team to investigate.

02 / FOLLOW THE MECHANISM

How a siem pipeline works

  1. Log sources

    stream logs via syslog, CloudWatch, S3 events, or API to the SIEM collector.

  2. Collector

    normalizes disparate formats (JSON, syslog key=value, Windows Event XML) into a common schema.

  3. Detection engine

    runs hundreds of rules in real-time — signature-based (known IoCs), behavioral (anomalous volume), and threat-intel enriched.

  4. SOC analyst

    triages alerts in a dashboard, pivots on IPs, users, and timestamps to determine if it's a real incident or a false positive.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

check Wazuh SIEM agent status

wazuh-control status

EXAMPLE 02 · REFERENCE

search for AWS console logins in Splunk

splunk search 'index=aws sourcetype=cloudtrail eventName=ConsoleLogin'

Explore command anatomy in the CLI lab