Skip to content

Commit b7df3c6

Browse files
Update _posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md
Co-authored-by: Nathan Bower <[email protected]> Signed-off-by: DattellConsulting <[email protected]>
1 parent 95af12a commit b7df3c6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ OpenSearch is well suited for log analysis because it can ingest and index massi
4545
Security teams benefit from being able to query recent and historical logs in one place. For example, an analyst can query web server logs, DNS logs, and authentication logs simultaneously to investigate an incident, something that would be cumbersome if those logs resided in separate silos.
4646

4747
### <u>Data normalization</u>
48-
Data normalization is important for building generalizable detection rules and dashboards that work across different log sources. When aggregating logs from many sources, a common challenge is that each source has its own format (different field names and structures). OpenSearchs Security Analytics plugin includes field mappings for common log types.[1](https://opensearch.org/docs/latest/security-analytics/#:~:text=Security%20Analytics%20is%20a%20security,responding%20effectively%20to%20potential%20threats) Additionally, OpenSearch allows users to define mappings and ingest pipelines to normalize data.
48+
Data normalization is important for building generalizable detection rules and dashboards that work across different log sources. When aggregating logs from many sources, a commonly encountered challenge is that each source has its own format (different field names and structures). OpenSearch's Security Analytics plugin includes field mappings for common log types.[1](https://opensearch.org/docs/latest/security-analytics/#:~:text=Security%20Analytics%20is%20a%20security,responding%20effectively%20to%20potential%20threats) Additionally, OpenSearch allows users to define mappings and ingest pipelines to normalize data.
4949

5050
### <u>Data Visualization.</u>
5151
Once logs are indexed and normalized, analysts can create visualizations with OpenSearch Dashboards to enhance situational awareness. For example, users can build charts showing trends of failed logins over time or a geographic map of login locations.

0 commit comments

Comments
 (0)