SIEM
SIEM Dashboard
The single shared environment every role works in. All modules query this same dataset.
Total Events
1,248,209
window 24h
Events / second
21,910
peak 34,102
Alert Volume
36
raised by 6 rules
Auth Failures
3,481
+38% vs baseline
Event & alert volume
Hourly ingestion vs detections
Alert severity mix
Source distribution
Top talkers
Source and destination IPs by volume
- 10.20.14.61WS-FIN-01448,211
- 10.20.3.10SRV-DC-0139,044
- 185.220.101.44External · flagged C21,842
- 10.20.8.22SRV-WEB-0215,320
- 45.133.1.87External · spray source942
Ingestion health
17 configured log sources
- Windows Event LogEndpoint1840 eps · Healthy
- SysmonEndpoint2410 eps · Healthy
- Linux AuditEndpoint430 eps · Healthy
- EDREndpoint690 eps · Degraded
- FirewallNetwork3120 eps · Healthy
- IDS / IPSNetwork210 eps · Healthy
- DNSNetwork2870 eps · Healthy
- ProxyNetwork1560 eps · Healthy
- VPNNetwork120 eps · Healthy
- NetFlowNetwork4300 eps · Lagging
- Active DirectoryIdentity980 eps · No Data
- Entra IDIdentity540 eps · Healthy
- Web ServerApplication1330 eps · Healthy
- DatabaseApplication260 eps · Healthy
- Email Security GatewayEmail310 eps · Healthy
- AWS CloudTrailCloud470 eps · Healthy
- Azure ActivityCloud380 eps · Healthy
Learn this capability
Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.
Intermediate · Simulation · 25 min
Diagnosing a silent log source
The domain controller source has sent no events for two hours. Detection coverage for authentication is effectively off.
Intermediate · Theory · 18 min
SIEM architecture overview
You keep the SIEM healthy. Everything analysts do depends on data arriving, parsing correctly and being searchable.
Advanced · Theory · 20 min
SOC metrics that matter
You report to the CISO monthly. Choosing the wrong metrics drives the wrong analyst behaviour.