<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Learning SIEM basics in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241153#M1645</link>
    <description>&lt;P&gt;My advice: do not think about product, but think about your needs: what are the risk for your company, mainly the business ones ?&lt;BR /&gt;
Then, you will be able to identify scenarios you want to detect (for the correlation), check you want to do (for compliance), and what kind of anomalies you want to identify (for the analytic part).&lt;BR /&gt;
So SIEM is just a tool that does not answer all security needs. That said, you might have a look to &lt;A href="http://docs.splunk.com/Documentation/ES"&gt;ES documentation&lt;/A&gt; and look for .conf presentation for real use case.&lt;/P&gt;</description>
    <pubDate>Mon, 09 May 2016 08:18:43 GMT</pubDate>
    <dc:creator>mdessus_splunk</dc:creator>
    <dc:date>2016-05-09T08:18:43Z</dc:date>
    <item>
      <title>Learning SIEM basics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241152#M1644</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I now have fairly good experience with Splunk and want to learn more about SIEM but not sure where to start. I am from application side and have handled various applications in the past. I want to learn SIEM basics so that I have good idea when dealing with Splunk SIEM.&lt;/P&gt;

&lt;P&gt;Any help or pointer is greatly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Hemendra&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 08:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241152#M1644</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2016-05-09T08:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Learning SIEM basics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241153#M1645</link>
      <description>&lt;P&gt;My advice: do not think about product, but think about your needs: what are the risk for your company, mainly the business ones ?&lt;BR /&gt;
Then, you will be able to identify scenarios you want to detect (for the correlation), check you want to do (for compliance), and what kind of anomalies you want to identify (for the analytic part).&lt;BR /&gt;
So SIEM is just a tool that does not answer all security needs. That said, you might have a look to &lt;A href="http://docs.splunk.com/Documentation/ES"&gt;ES documentation&lt;/A&gt; and look for .conf presentation for real use case.&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 08:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241153#M1645</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2016-05-09T08:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Learning SIEM basics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241154#M1646</link>
      <description>&lt;P&gt;Thanks mdessus for your input. I will follow above tip.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 00:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Learning-SIEM-basics/m-p/241154#M1646</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2016-05-10T00:31:53Z</dc:date>
    </item>
  </channel>
</rss>

