A security analyst is configuring a new Security Information and Event Management (SIEM) solution. Place the core stages of the SIEM log processing pipeline in the correct sequential order from initial log entry to analyst notification.
- 1Log Collection
- 2Parsing
- 3Normalization
- 4Correlation
- 5Alerting
Cevap
The correct sequence of stages in a SIEM log processing pipeline is: Log Collection, Parsing, Normalization, Correlation, and Alerting.
In a standard SIEM processing pipeline, raw log data is gathered via Log Collection, extracted into data fields via Parsing, converted to a unified taxonomy during Normalization, cross-analyzed against rules during Correlation, and dispatched to analysts during Alerting.
Adım Adım Çözüm
Anahtar Kavram
SIEM Log Processing Pipeline