Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

📖 Send logs to XSIAM SoC #5581

Open
4 tasks
darren1988 opened this issue Oct 8, 2024 · 2 comments
Open
4 tasks

📖 Send logs to XSIAM SoC #5581

darren1988 opened this issue Oct 8, 2024 · 2 comments
Assignees
Labels

Comments

@darren1988
Copy link

darren1988 commented Oct 8, 2024

User Story

As a Security Operations Centre (SoC),
I want to collect and centralise security logs from all relevant systems, applications, and network devices,
so that we have a unified source of data for threat detection, correlation, and analysis.…

Value / Purpose

The centralisation of security logs provides a comprehensive overview of our security posture, enabling the Security Operations Centre (SoC) to:

Enhance Threat Detection: By aggregating logs from various sources, we can identify patterns and anomalies that may indicate potential security threats more effectively.

Improve Incident Response: Centralised logs allow for quicker analysis and response to incidents, minimising potential damage and downtime.

Facilitate Compliance: A unified log source helps ensure that we meet regulatory requirements and industry standards for security monitoring and reporting.

Support Forensic Investigations: In the event of a security breach, having all relevant logs in one place allows for thorough investigations and root cause analysis.

Enable Correlation of Events: By correlating logs from different systems, we can gain insights into complex attack vectors and multi-stage attacks that would be difficult to detect in siloed environments.

No response

Useful Contacts

Tevin Jemide & Darren Rooke

User Types

No response

Hypothesis

If we... [do a thing]
Then... [this will happen]

Proposal

No response

Additional Information

No response

Definition of Done

Example - [ ] Documentation has been written / updated

  • README has been updated
  • User docs have been updated
  • Another team member has reviewed
  • Tests are green
@tjemideGH tjemideGH self-assigned this Oct 8, 2024
@tjemideGH
Copy link

I am currently reviewing the incident logs.

@tjemideGH
Copy link

I have completed the review and will send the result to the SOC team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: 👀 TODO
Development

No branches or pull requests

2 participants