2.1 What is SIEM?

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with

Already have an account? Sign In »

1 hour 27 minutes
Video Transcription
Welcome to Module one. What is the scene
in this video? You will learn about what a seam is and what seemed tools are commonly used for. If you don't know you're on the right. Please,
before we begin a pre assessment question.
True or false, a theme is only used to monitor network traffic.
If you answered false, you were correct. A scene can be used for a variety of things. Let's jump in and see what
a seam is. A security information. An event management tool. This is a tool that helps us to monitor our network traffic and provide real time analysis of security alerts produced by the applications and is critical to the monitoring of in continuous improvement of security.
It is usually comprised of different types of smaller tools. Ah, log management system, for instance, would collect a log data from various systems and applications like workstations, firewalls, servers, et cetera.
A security event manager will focus on real time logs gathered by security and network devices in order to correlate security events.
A security of meant correlation will examine patterns and log files and flag potential threats,
and in combination of these tools, can make up the seam, which centralizes storage and analysis of not only traffic but many different log types.
So why do I need a seam?
Seamus? A hopeful tool and many sizes and types of environments. It can allow for a lateral or bird side view of IC activity, which will generally organized logs and information into a hetero genius view so that many different sources of information can be managed and seen at once.
It can also normalize activity to readable data and match it to certain specifications that a user or even vendor have to find
in order to make it more easily understood.
In case of an attack. It can help to run analysis on what data was breached or potentially compromised.
It can also easily set rules or parameters in order to block further attacks.
When you have applications running, they will generate data as they function. This data will be forwarded to a seat and be a collector or forward or indifferent. Four months
the seam, then Agra Gates and consolidates input and format data into actionable output.
User can use the seem to take these raw logs of data and display and filter any specific information you do or don't want shown.
This allows for an easier to understand dashboard of important information.
Once filtered, analysis and correlation can be performed by our teams.
As a note, these applications generates so much data that it would be overwhelming if all of it were to be interpreted. This is why steam tools are not only important but necessary and larger organizations with more applications and data.
In today's brief lecture, we discussed what a seam is and how it might be used.
Common uses for a seam tool in organizations of all different sizes. And why seemed tools They're helpful in organizing data pulled from logs.
Up Next
Introduction to SIEM Tools

In this SIEM training course, students will learn the basics of a Security Information Event Manager (SIEM) and how and why these are used in a security operations center (SOC).

Instructed By