Skip to content

Latest commit

 

History

History
16 lines (12 loc) · 1.14 KB

File metadata and controls

16 lines (12 loc) · 1.14 KB

Real-World SIEM Lab: Simulating Detection and Incident Response

This project aims to establish a robust and scalable centralized log management infrastructure using verious techologies. By deploying logcollection agents across various endpoints, firewalls, and IDS/IPS devices, we will efficiently collect and aggregate security and operational logs. This centralized repository will enable comprehensive analysis, threat detection, compliance reporting, and incident response.

Lab Logical Diagram

Installation and Configuration

  • Deploy Active Directory, Splunk Server and Universal Forwarders on relevant systems.

Data Ingestion

  • Configure Universal Forwarders to collect logs from endpoints, firewalls, IDS/IPS, and other sources.

Data Analysis

  • Utilize Splunk's search processing language (SPL) to analyze logs, identify patterns, and detect anomalies.

Alerting and Reporting

  • Create custom alerts and dashboards to proactively respond to security incidents.