You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: _posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md
+1-1
Original file line number
Diff line number
Diff line change
@@ -50,7 +50,7 @@ Data normalization is important for building generalizable detection rules and d
50
50
### <u>Data visualization</u>
51
51
Once logs are indexed and normalized, analysts can create visualizations with OpenSearch Dashboards to enhance situational awareness. For example, users can build charts showing trends for failed logins over time or a geographic map of login locations.
52
52
53
-
### <u>Search.</u>
53
+
### <u>Search</u>
54
54
OpenSearch Dashboards supports interactive querying. A security analyst can filter the view to a specific timeframe or drill down on a particular host or user to see all related events.
55
55
56
56
OpenSearch’s search capabilities also enable ad-hoc log analysis and threat hunting. Analysts can run queries to hunt for subtle signs of compromise that might not trigger an alert, such as searching across all logs for a particular filename associated with malware.
0 commit comments