Daily Operations
Topics
Practical Usage Examples
Daily Security Monitoring Workflow
Step 1: Start with Overview Dashboard
Navigate to SIEM → Overview
Check the “Total Alerts” chart for unusual spikes
Review “Top 5 Alerts” for immediate priorities
Use the slider to filter by severity if needed
Step 2: Investigate High-Priority Areas
If you see Windows issues, click Windows dashboard
If you see vulnerability spikes, click Vulnerabilities dashboard
If you see audit violations, click Audit dashboard
Step 3: Create Alerts for New Threats
Go to Alerts → Create Alert Rule
Give it a descriptive name
Choose appropriate rule type (Frequency for repeated events)
Set index pattern for your data
Define the rule logic
Set alert method (email, etc.)
Incident Investigation Workflow
Step 1: Identify the Incident
Review alerts in Alert Status tab
Check Overview dashboard for anomalies
Use time controls to focus on incident timeframe
Step 2: Gather Context
Switch to relevant dashboard (Windows/Linux/Audit)
Use filters to focus on affected systems
Review related events in the time window
Step 3: Analyze Impact
Check Vulnerabilities dashboard for related exposures
Review Audit dashboard for user activities
Use MITRE dashboard for attack technique mapping
Compliance Monitoring Workflow
Step 1: Select Compliance Framework
From main SIEM dashboard, click relevant compliance card
PCI DSS for payment processing
HIPAA for healthcare data
GDPR for EU personal data
NIST 800-53 for government standards
Step 2: Review Compliance Status
Each compliance dashboard shows current status
Review any violations or gaps
Export reports for documentation
Step 3: Address Issues
Create alerts for compliance violations
Set up regular monitoring workflows
Document remediation activities
Understanding Alert Severity and Risk
Risk Categories and Scores
Critical: 100 points - Immediate action required
Production: 90 points - Production system issues
VIP HOST: 80 points - High-value target issues
DB Server: 80 points - Database security issues
High: 75 points - Significant security concern
Medium: 50 points - Moderate security issue
Team A/B: 50 points - Team-specific alerts
Low: 25 points - Minor security event
Rule Levels Explained
Levels 1-3: Informational events
Levels 4-7: Low to medium priority
Levels 8-11: High priority - investigate promptly
Levels 12-15: Critical priority - immediate response required
Alert Volume Management
Use the slider on Overview dashboard to filter noise
Focus on levels 10+ for daily monitoring
Review levels 7-9 weekly for trends
Archive levels 1-6 for compliance only