Content ITV PRO
This is Itvedant Content department
Learning Outcome
4
Compare their features and use cases.
3
Describe Splunk and Wazuh architecture.
2
Differentiate commercial and open-source SIEMs.
1
Explain the purpose of SIEM in SOCs.
5
Explain the SIEM workflow from logs to response.
A city's emergency control room receives information from traffic cameras, emergency calls, police patrols, and fire stations in one place.
Different information sources = Logs and Security Events
Operators examine the information and notice an accident, fire, or other emergency.
Finding suspicious activity = Security Monitoring and Event Analysis
Once an emergency is confirmed, operators alert the appropriate police, fire, or medical team.
Notifying security analysts = Security Alerts
The teams investigate the situation and take the necessary action to control the emergency.
Investigation and action = Incident Response
Splunk and Wazuh work in a similar way. They collect security logs and events from computers, servers, firewalls, and applications. They analyze the data, detect suspicious activity, generate alerts, and help security teams investigate and respond to cyber incidents.
What is SIEM?
SIEM (Security Information and Event Management) tools collect, store, analyze, and monitor security data from systems, devices, and applications.
They provide centralized visibility to help security teams detect, investigate, and respond to threats.
Examples: Splunk, Wazuh, IBM QRadar, Microsoft Sentinel.
Role of SIEM in SOC
SOC teams use SIEM to:
Monitor security events
Detect threats
Investigate alerts
Analyze logs
Support incident response
SIEM also automates monitoring and analysis of large amounts of security data.
Why Organizations Use SIEM
Organizations generate large volumes of logs from servers, endpoints, firewalls, applications, and cloud services.
SIEM centralizes these logs, improves security visibility, speeds up threat detection, and supports compliance.
Popular SIEM Tools
Commercial SIEM
Commercial solutions provide advanced features, vendor support, and enterprise scalability.
Examples: Splunk, IBM QRadar, Microsoft Sentinel, LogRhythm.
Open-Source SIEM
Open-source solutions offer customizable security monitoring with lower licensing costs.
Examples: Splunk, IBM QRadar, Microsoft Sentinel, LogRhythm.
Other SIEM Platforms
Splunk
Log management, analytics, monitoring, and threat detection.
Smart Layouts
AI arranges content beautifully for better flow and impact
IBM QRadar
Log management, event correlation, and threat detection.
Microsoft Sentinel
Cloud-native SIEM and security analytics.
Wazuh
Log analysis, endpoint monitoring, vulnerability detection, and security monitoring.
What is Splunk?
Splunk is a data analytics and security monitoring platform that collects and analyzes machine-generated data.
It is widely used for SIEM, security monitoring, incident investigation, and threat detection.
Key Features
Log collection and indexing
Powerful search
Real-time monitoring
Alert generation
Splunk Architecture
Forwarders
Lightweight agents that collect logs and send them to Splunk.
Examples: Windows logs, Linux logs, application logs.
Indexers
Receive, process, and store data in searchable indexes.
Search Head
Provides the interface for searching data, creating dashboards, generating reports, and investigating incidents.
Splunk Dashboards
Display security information such as:
Alerts
Threat trends
Authentication activity
System events
Incident statistics
Search and Reporting
Splunk uses Splunk Processing Language (SPL) to search and analyze large datasets and supports automated reporting.
Splunk Use Cases:
Alerts
Threat trends
Authentication activity
System events
Incident statistics
What is Wazuh?
Wazuh is an open-source security platform for security monitoring, threat detection, endpoint protection, and log analysis.
It supports both on-premises and cloud environments.
Key Features
Log analysis
Endpoint monitoring
File integrity monitoring
Vulnerability detection
Security configuration assessment
Wazuh Architecture
Wazuh Agent
Installed on endpoints to collect security information and send it to the Wazuh Manager.
Wazuh Manager
Processes agent data, applies detection rules, and generates alerts.
Wazuh Indexer
Stores and indexes security data for searching and analysis.
Wazuh Dashboard
Provides a web interface for monitoring events, investigating alerts, and managing Wazuh.
Wazuh Monitoring
Includes:
Endpoint monitoring
Log monitoring
File integrity monitoring
Vulnerability monitoring
Security configuration monitoring
Wazuh Use Cases
Endpoint security
Vulnerability management
Threat detection
Compliance monitoring
File integrity monitoring
Splunk vs Wazuh
The choice depends on budget, requirements, and infrastructure.
Common SIEM Functions
Log Search
Allows analysts to search logs for suspicious activity and investigate incidents.
Alert Generation
Creates alerts when detection rules identify suspicious activity.
Dashboard Visualization
Log Collection
Collects logs from endpoints, servers, applications, network devices, and cloud services.
Threat Detection
Analyzes events and applies rules to identify malicious activity.
Displays security information through charts, graphs, and reports.
SIEM Workflow
Data Collection
Log Ingestion
Event Analysis
Alert Generation
Investigation
Data Collection
Gather security data from different sources.
Send logs to the SIEM for processing and storage.
Analyze events using rules and analytics.
Generate alerts for suspicious activity.
Analysts examine alerts and logs.
Provide information for incident response and remediation.
Benefits of SIEM
Centralized Visibility: Monitors security activities in one place.
Faster Detection: Identifies suspicious activity quickly.
Improved Investigation: Provides historical and detailed event data.
Compliance Support: Supports logging, retention, and reporting.
Monitoring Efficiency: Automates monitoring and analysis.
Challenges of SIEM
Large Data Volumes:
Requires significant processing and storage.
Alert Fatigue:
High alert volumes can overwhelm analysts.
Rule Tuning:
Rules require continuous adjustment.
Resource Requirements:
Needs skilled personnel and infrastructure.
Learning Curve:
Analysts need time to learn SIEM tools and workflows.
Summary
5
SIEM tools improve SOC operations and incident response.
4
Both support logging, alerting, investigation, and threat detection.
3
Wazuh is an open-source platform with strong endpoint monitoring.
2
Splunk is a commercial SIEM with powerful search and analytics.
1
SIEM tools collect, analyze, and monitor security events.
Quiz
Which of the following is an open-source SIEM platform?
B. IBM QRadar
C. Microsoft Sentinel
D. Wazuh
A. Splunk
Quiz-Answer
D. Wazuh
Which of the following is an open-source SIEM platform?
A. Splunk
B. IBM QRadar
C. Microsoft Sentinel
By Content ITV