JELAJAH SOC
YO

SIEM

SIEM Dashboard

The single shared environment every role works in. All modules query this same dataset.

Open Log Explorer

Total Events

1,248,209

window 24h

Events / second

21,910

peak 34,102

Alert Volume

36

raised by 6 rules

Auth Failures

3,481

+38% vs baseline

Event & alert volume

Hourly ingestion vs detections

Alert severity mix

Source distribution

Top talkers

Source and destination IPs by volume

  • 10.20.14.61WS-FIN-01448,211
  • 10.20.3.10SRV-DC-0139,044
  • 185.220.101.44External · flagged C21,842
  • 10.20.8.22SRV-WEB-0215,320
  • 45.133.1.87External · spray source942

Ingestion health

17 configured log sources

  • Windows Event LogEndpoint1840 eps · Healthy
  • SysmonEndpoint2410 eps · Healthy
  • Linux AuditEndpoint430 eps · Healthy
  • EDREndpoint690 eps · Degraded
  • FirewallNetwork3120 eps · Healthy
  • IDS / IPSNetwork210 eps · Healthy
  • DNSNetwork2870 eps · Healthy
  • ProxyNetwork1560 eps · Healthy
  • VPNNetwork120 eps · Healthy
  • NetFlowNetwork4300 eps · Lagging
  • Active DirectoryIdentity980 eps · No Data
  • Entra IDIdentity540 eps · Healthy
  • Web ServerApplication1330 eps · Healthy
  • DatabaseApplication260 eps · Healthy
  • Email Security GatewayEmail310 eps · Healthy
  • AWS CloudTrailCloud470 eps · Healthy
  • Azure ActivityCloud380 eps · Healthy

Learn this capability

Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.