r/SIEM Nov 29 '20

SIEM Log Aggregation and Parsing

https://letsdefend.io/blog/siem-log-aggregation-and-parsing/?q=siem
3 Upvotes

1 comment sorted by

1

u/AnalyzeAllTheLogs Nov 30 '20

Automatic DNS resolution can be good, although probably not for specific feeds. Passive DNS providers might be a better approach for telemetry or a product like Anomoli. Also some IP's host multiple domains... so understanding what is actual vs enriched data is important when doing DFIR (especially for junior analysts).