SIEM / SOC Integration

Aggregate security events and logs for correlation and investigation.

What SIEM integration does

Aggregate security events and logs from across your estate for correlation and investigation. Connect your SOC tooling to surface threats and maintain an audit-ready security timeline.

Connecting a source

  1. Go to Monitoring β†’ SIEM Integration.
  2. Add the log source with its type and the client company it belongs to.
  3. Save. Events from that source are collected against the client.

Investigating

Events are correlated so a pattern across several devices reads as one story rather than a list of unrelated lines. When investigating:

  1. Start from the earliest event, not the loudest one.
  2. Follow the affected account or device through the timeline.
  3. Note what you checked as you go β€” the timeline is your evidence later.

Retention and audit

The event timeline is what makes an incident defensible after the fact. Do not prune it to make a dashboard cleaner.

Tip: Connect authentication logs first. The overwhelming majority of incidents you will investigate start with a sign-in that should not have succeeded.

Was this article helpful?

SIEM / SOC Integration β€” Device Monitoring | Plenix Docs | Plenix Docs