SIEM Data Models
The schemas and structures SIEMs use to normalize events from many sources into common fields, so queries and detections work across them rather than re-implementing per source.
Concept Neighborhood
Explore this concept’s connections in the groups below.
Start here
Detection engineering
A related concept to explore, covered by 16 lessons.
Detection engineeringStart here
16
lessons
Structured Logging
6
lessons
Kusto Query Language
5
lessons
Log Source Taxonomy
5
lessons
Query Performance
5
lessons
SIEM
5
lessons
Show 1 more connection
Related Lessons
5 lessons cover this conceptSIEM Data Models and Log Normalization
SOC Analyst
Aggregation and Statistical Analysis for Threat Detection
SOC Analyst
Time-Series Analysis and Multi-Source Correlation
SOC Analyst
Query Tuning, Lookup Tables, and Production Operations
SOC Analyst
Designing a Detection Program with SIEM Queries
SOC Analyst
Sign in to open lesson content directly.
