SIEM platforms
The central nervous system that spots an attack across thousands of log sources.
What it is
About SIEM platforms
SIEM (Security Information and Event Management) platforms like Splunk, IBM QRadar, Microsoft Sentinel and Elastic Security aggregate and correlate log data across an organisation's infrastructure to detect and investigate security threats. They're the core tool in a Security Operations Centre (SOC) for real-time threat detection, incident investigation and compliance reporting, turning an overwhelming volume of raw logs into actionable alerts.
What you can do with it
Capabilities
Aggregate and correlate log data across an entire IT estate
Build and tune detection rules for known attack patterns
Investigate and triage security alerts during an incident
Produce compliance and audit reporting from log data
Hunt proactively for indicators of compromise across historical logs
How to learn it
Learning Resources
Splunk's free Splunk Fundamentals training and Splunk>Boss of the SOC practice datasets
Microsoft Learn's free Microsoft Sentinel training paths
TryHackMe and Blue Team Labs Online SOC-analyst learning paths
Setting up a free home-lab SIEM like Wazuh or the ELK stack against sample attack logs
Pro Tip
Spend more time tuning detection rules to your own environment's normal traffic than adding new rules — an under-tuned SIEM drowns analysts in false positives, which is why real alerts get missed.
Skills that use this tool
Roles that use this tool