Security information and event management (SIEM) helps monitor cloud infrastructure at an API level, using integration modules that are able to pull security data from well-known cloud providers, such as Amazon AWS, Azure, or Google Cloud. In addition, SIEM provides rules to assess the configuration of your cloud environment, easily spotting weaknesses.
In addition, SIEM lightweight and multi-platform agents are commonly used to monitor cloud environments at the instance level.
An open source cybersecurity platform that integrates SIEM and XDR in a unique solution.
The SIEM indexer is a highly scalable full-text search and analysis engine.
It is responsible for indexing and storing alerts generated by the SIEM server. It can be installed as a single-node or multi-node cluster, depending on the environment needs.
A flexible and intuitive web interface for data mining, analysis, and visualization.
The dashboard is used to manage the SIEM configuration and monitor its status.
The server manages the agents, configuring and updating them remotely when necessary. This component analyzes the data received from the agents, processing it through decoders and rules and using threat intelligence to look for indicators of compromise.
The SIEM agent is a multi-platform component that runs on the endpoints to be
monitored. It provides prevention, detection, and response capabilities.
© | The Arthur Corp