December 2017
Intermediate to advanced
410 pages
11h 5m
English
Every application has a different way of logging data, which might be a common event. For example, a failed login attempt in OpenVPN server might generate completely different log formats and data compared to failed login attempts in the SSH server. However, as a security engineer, you might want to know the failed events across all the applications and servers in your organization.
Many of the SIEM tools come with prebuilt templates, which will map these granular events to high-level events. So, in such a case, if we query Failed Attempts, then the SIEM solution will show us failed attempts of all the devices such as OpenVPN, SSH, FTP, firewalls, AWS, and AD. This makes life much simpler, but SIEM ...
Read now
Unlock full access