SIEM Investigation Workflow
The standard pattern analysts follow to investigate alerts and incidents in a SIEM, gathering context, pivoting across data, and building a timeline using the SIEM's query and visualization tools.
Concept Neighborhood
Explore this concept’s connections in the groups below.
Start here
Multi-Source Correlation
A related concept to explore, covered by 9 lessons.
Multi-Source CorrelationStart here
9
lessons
Triage Methodology
7
lessons
SIEM
5
lessons
SOC Leadership Communication
5
lessons
Investigation
3
lessons
Pivoting
3
lessons
Show 1 more connection
Related Lessons
5 lessons cover this conceptSIEM Data Models and Log Normalization
SOC Analyst
Aggregation and Statistical Analysis for Threat Detection
SOC Analyst
Time-Series Analysis and Multi-Source Correlation
SOC Analyst
Query Tuning, Lookup Tables, and Production Operations
SOC Analyst
Designing a Detection Program with SIEM Queries
SOC Analyst
Sign in to open lesson content directly.
