JELAJAH SOC
YO

Engineering track

SIEM Engineering

Own the pipeline: onboard sources, normalise fields, keep ingestion healthy and data quality high.

Configured sources

17

Total EPS

21,820

Unhealthy sources

3

Parse failure rate

0.42%

Data source management

SourceGroupTypeEPSHealth
Windows Event LogEndpointwindows1,840Healthy
SysmonEndpointsysmon2,410Healthy
Linux AuditEndpointlinux_audit430Healthy
EDREndpointedr690Degraded
FirewallNetworkfirewall3,120Healthy
IDS / IPSNetworkids210Healthy
DNSNetworkdns2,870Healthy
ProxyNetworkproxy1,560Healthy
VPNNetworkvpn120Healthy
NetFlowNetworknetflow4,300Lagging
Active DirectoryIdentityad980No Data
Entra IDIdentityentra540Healthy
Web ServerApplicationweb1,330Healthy
DatabaseApplicationdb260Healthy
Email Security GatewayEmailemail310Healthy
AWS CloudTrailCloudaws470Healthy
Azure ActivityCloudazure380Healthy

Parser lab

Extract named fields from a raw event

Sample event

<134>Aug 29 09:12:44 fw-edge-01 SFW: allow src=10.20.14.61 dst=185.220.101.44 spt=51422 dpt=443 proto=TCP act=ALLOW bytes=8421

Log onboarding checklist

  1. 1.Identify source, format and transport
  2. 2.Confirm time zone and timestamp format
  3. 3.Build and validate the parser
  4. 4.Map to the normalised schema (ECS-like)
  5. 5.Validate field coverage against detections
  6. 6.Enable and monitor for 24h

Data quality

  • Missing host.name1.8%
  • Unparsed events0.42%
  • Clock skew > 60s3 sources
  • Silent sources (24h)Active Directory