A Log Aggregation Design Criteria for Robust SIEM (Security Information and Event Management) in Enhancing Threat Detection
Mohsen Mohamad Hata, Mohamad Yusof Darus, Muhammad Zul Akmal Bin Shafiee, Elvisianah Petrus, Yasmin Athira Jamian · 2023
Security Operations Centers (SOCs) play a vital role in protecting organizations from cyber threats. Supported by skilled Security Analysts, they are the first line of defense, monitoring and responding to incidents. The Security Information and Event Management (SIEM) system is a critical tool for managing log data efficiently. This research focuses on optimizing log data aggregation within a SOC's SIEM framework. By exploring various log aggregation techniques, we aim to enhance the performance of data collectors, leading to quicker response times and improved security. This research contributes to a more robust defense against the ever-changing landscape of cyber threats. It empowers organizations to face evolving challenges with confidence and resilience.