top of page
To test this feature, visit your live site.
What are the recommended event types to forward to a SIEM for Log Management from a Security SOC perspective?
What are the recommended event types to forward to a SIEM for Log Management from a Security SOC perspective?
2 answers0 replies
Comments (2)
Forum: Forum
bottom of page
I'd say this is very much one of those 'it depends' questions. Some security teams are going to want as much data as you're willing to provide, and some will have very detailed things they're wanting to see. Depending upon the SIEM solution there's also a financial aspect as some vendors charge on your ingest volume and even in a moderately sized environment the PANW firewalls can be chatty.
You may want to ask that on the forum so more people can chime in :) I personally don't have extensive soc experience so might miss some interesting ones I'd forward high and critical threats, critical system events, config changes and specific rules for highly sensitive resources