Defensive Security (Blue Team) / Detection
Lesson 18 of 32
SIEM
A SIEM collects logs from everywhere, searches them and raises alerts on suspicious patterns. Splunk, Microsoft Sentinel, Elastic and Wazuh are common.
Key points
- Central log search
- Correlation rules spot patterns
- Wazuh is free and open source
Quiz · +10 XP
What does a SIEM do?
Log in to save progress and earn XP.