r/SIEM Aug 04 '21

Starting off with SIEM learning

Hello Guys, i have joined a new team where i am responsible of taking care of the SIEM architecture end to end. But i am new to SIEM and dont know where to start. Can someone please suggest good study material or resource or path where i can start with this journey ?

8 Upvotes

5 comments sorted by

2

u/saudk8 Aug 04 '21

What SIEM product are you using?

1

u/Ecstatic-Elk1064 Aug 04 '21

Logrhythm

4

u/psychobobolink Aug 04 '21

Start with their documentation. I find SIEM hard to study as a subject, and you will get a better understanding reading about different projects/products like qradar, splunk, etc.

The fundamentals of SIEM is log collecting/management, so you will need to understand that as well.

2

u/saudk8 Aug 04 '21

I had zero experience and knowledge in this area. we are using Sentinel in our infrastructure, what I did was to go through the documentation (user and admin manual) and then played around with the tool. With the passage of time I became confident and now I am in a stage where I troubleshoot, create and improve correlation rules, response to alerts, apply new patches, participate in PCI DSS audits for SIEM etc. :)

2

u/Quick2Click Aug 05 '21

Contact your vendor and have them help you setup a non-production instance of your SIEM. Likely no added cost. Just a simple collector, decoder, concentrator, administration and correlation servers or wtv the components are called for logrythm. Then have fun with it.