A security engineer is designing an enterprise Security Information and Event Management (SIEM) log pipeline to ingest data from heterogeneous sources. Place the stages of the log processing life cycle in the correct chronological order from initial log intake to incident detection notification.
- 1Log Collection & Ingestion
- 2Parsing & Normalization
- 3Aggregation & Indexing
- 4Correlation Engine Processing
- 5Alerting & Escalation
Cevap
The correct sequential order of log processing within a SIEM pipeline is: Log Collection & Ingestion, Parsing & Normalization, Aggregation & Indexing, Correlation Engine Processing, and Alerting & Escalation.
In a modern SIEM architecture, log data must flow logically from capture (ingestion) to field mapping (normalization), centralized storage indexing (aggregation), threat pattern evaluation (correlation), and finally analyst notification (alerting).
Adım Adım Çözüm
Anahtar Kavram
SIEM Log Processing Pipeline