Implementation Of A SIEM System Using Splunk And The Enterprise Security Module And Analysis Of Its Effectiveness In Detecting Cyber Threats

Maciej Kozak, Anna Plichta · 2025

The article focuses on the implementation and configuration of the Splunk Enterprise Security SIEM (Security Information and Event Management) system in a test environment. The objective of the research was to analyze the system's effectiveness in detecting cyber threats, its practical application, and optimization possibilities. As part of the experiments, simulations of real-world attacks—such as brute-force attempts, privilege escalation, and network configuration changes—were conducted to verify the effectiveness of custom detection rules. The study included a detailed assessment of the SIEM architecture, the process of creating and optimizing detection rules, and an analysis of the system's effectiveness in threat detection. Particular attention was given to the issue of false positives and methods for their minimization. Additionally, challenges related to log configuration and management were analyzed, and the impact of customized detection rules on the system's overall efficiency was evaluated. The analysis results indicate that proper configuration of the SIEM system can significantly enhance IT security by reducing detection and response times for incidents. However, the system's effectiveness largely depends on its adaptation to the specific requirements of an organization. The conclusions drawn from this research can serve as a foundation for further work on optimizing SIEM systems and integrating them with advanced automation and behavioral analysis technologies.

Read the paper · More papers on PaperTik