SECURITY INFORMATION
AND EVENT
MANAGEMENT
SIEM
WHAT IS SIEM
LOG aggregation
 Centralized all security notifications from various
security technology (Firewalls ,IDs ,IPs ,Antivirus
console ,wireless active points and active
directories).
 It all generate tons of notification every day.
 Siem allows you to centralize all logs in one place
in set of report.
Add a Footer 2
HOW IT WORKS
Event management
RULES
• Repeat Attack-Login Source
• Brute force attacks, Password guessing
• Alert on 3 or more failed logins in 1 minute
from a single host.
• Active Directory, Syslog (Unix Hosts,
Switches, Routers, VPN)
3
RULE
GOAL
Trigger
Event
HOW IT WORKS
N o t i f i c a t i o n
 Simply logged
 Written in report to be viewed later
 Immediate Attention
4
I n c i d e n t
 Sent by email / api
 How they can solve it
5
6
7
Threats / Alerts
8
9
THANK YOU
10

SIEM (Security Information and Event Management)

  • 1.
  • 2.
    WHAT IS SIEM LOGaggregation  Centralized all security notifications from various security technology (Firewalls ,IDs ,IPs ,Antivirus console ,wireless active points and active directories).  It all generate tons of notification every day.  Siem allows you to centralize all logs in one place in set of report. Add a Footer 2
  • 3.
    HOW IT WORKS Eventmanagement RULES • Repeat Attack-Login Source • Brute force attacks, Password guessing • Alert on 3 or more failed logins in 1 minute from a single host. • Active Directory, Syslog (Unix Hosts, Switches, Routers, VPN) 3 RULE GOAL Trigger Event
  • 4.
    HOW IT WORKS No t i f i c a t i o n  Simply logged  Written in report to be viewed later  Immediate Attention 4 I n c i d e n t  Sent by email / api  How they can solve it
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.