Cyber Security

Security information and event management (SIEM) helps monitor cloud infrastructure at an API level, using integration modules that are able to pull security data from well-known cloud providers, such as Amazon AWS, Azure, or Google Cloud. In addition, SIEM provides rules to assess the configuration of your cloud environment, easily spotting weaknesses.

In addition, SIEM lightweight and multi-platform agents are commonly used to monitor cloud environments at the instance level.

Discover SIEM, the all-in-one security platform

An open source cybersecurity platform that integrates SIEM and XDR in a unique solution.

Central Components

SIEM indexer

The SIEM indexer is a highly scalable full-text search and analysis engine.

It is responsible for indexing and storing alerts generated by the SIEM server. It can be installed as a single-node or multi-node cluster, depending on the environment needs.

SIEM dashboard

A flexible and intuitive web interface for data mining, analysis, and visualization.

The dashboard is used to manage the SIEM configuration and monitor its status.

SIEM server

The server manages the agents, configuring and updating them remotely when necessary. This component analyzes the data received from the agents, processing it through decoders and rules and using threat intelligence to look for indicators of compromise.

Endpoint Security Agent

SIEM agent

The SIEM agent is a multi-platform component that runs on the endpoints to be

monitored. It provides prevention, detection, and response capabilities.

...

Deployment Options

© | The Arthur Corp