Lazo Lab Sign up

Defensive Security (Blue Team) / Detection

Lesson 18 of 32

SIEM

A SIEM collects logs from everywhere, searches them and raises alerts on suspicious patterns. Splunk, Microsoft Sentinel, Elastic and Wazuh are common.

Key points

  • Central log search
  • Correlation rules spot patterns
  • Wazuh is free and open source
Watch a video on thisOpens YouTube search results for “SIEM” in a new tab

Quiz · +10 XP

What does a SIEM do?

Log in to save progress and earn XP.