Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
SOC Analysis with SIEM
Rating: 4.5 out of 5(6 ratings)
1,005 students

SOC Analysis with SIEM

Mastering SIEM & Log Event Monitoring
Last updated 5/2025
English

What you'll learn

  • Learn the basics of how a Security Operations Center (SOC) works
  • Analyze logs from multiple sources to identify potential security incidents
  • Use SIEM tools to correlate data, investigate alerts, and generate incident reports
  • Apply threat detection techniques to triage and respond to cybersecurity events

Course content

1 section28 lectures1h 41m total length
  • Introduction to SIEM3:53

    Learn the defensive side of cybersecurity by tracing the evolution from security information management to security event management, log management, and siem, using Splunk in a cloud-based lab.

  • Why SIEM?2:18

    Understand why organizations need SIEM to monitor logs, prioritize events, normalize and correlate data, detect breaches, and meet compliance with Splunk.

  • Security Operations Center (SOC)4:26

    Explore how a security operations center uses siem to monitor events, detect anomalies, investigate root causes, manage logs, and drive proactive threat monitoring through pen testing and vulnerability assessment.

  • How SIEM Works3:26

    Discover how a SIEM collects, stores, analyzes, and reports on logs from diverse sources, normalizes data, correlates events, and alerts on security incidents.

  • Why is SIEM Important?1:17

    prioritize events and spot security issues using siem to manage vast data from machine events. normalize and correlate raw machine events, and add indexes to enable search and reporting.

  • SIEM Architecture1:42

    Explore the SIEM architecture as system input from endpoints and network devices feeds a scene that collects event data and contextual data, denormalizes and aggregates logs for a searchable dashboard.

  • SIEM Events Workflow4:11

    See how siem collects logs from firewalls, servers, endpoints, and cloud sources, routes them to a receiver, normalizes and aggregates, then indexes and displays them in a searchable dashboard.

  • Features of a SIEM1:01

    Explore the features of a next-generation SIEM, including log collection and analysis, event correlation, log forensic reporting, dashboards, user activity monitoring, real-time alerting, log retention, and integrity monitoring.

  • Critical Events to Monitor7:08

    Identify critical events to monitor, such as new processes, PowerShell use, suspicious logons, and possible lateral movement, then investigate file share activity, new services, registry changes, and data exfiltration indicators.

  • Summary Table of Critical Events to Monitor2:35

    Learn to monitor Windows event IDs, including new process and logon activities, and recognize firewall network events and registry changes that indicate malware, exfiltration, or privilege abuse.

  • Six Ways a SIEM Can Help Stop Threats1:05

    Discover six siem-made protections against threats: detect compromised credentials; anomalous privilege escalation; command and control; data exfiltration; usb drive insertion via personal email; and rapid encryption and lateral movements.

  • Splunk Enterprise7:31

    Learn how Splunk powers SIEM with forwarders, indexers, and search heads to collect and index logs from endpoints in real time, using apps and API integrations.

  • Splunk Fields2:31

    Explore Splunk fields, including selected and interesting fields, and learn how hosts, sources, and source types shape log searches and event displays in SIEM workflows.

  • Search Language Syntax1:56

    Learn how to search Splunk events with its search language syntax, set index to web, specify source type, and use pipes, built-in commands, and concatenate results to calculate fields.

  • Search Best Practices8:43

    Learn Splunk search best practices for siem: set time frames and indices, use precise terms, dedupe duplicates, avoid leading wildcards, and present results with table and stats.

  • Splunk Installation2:26

    Sign up for Splunk Cloud, create an account with a valid email, and update your temporary password, then learn to upload logs by re-uploading a Linux log source in Splunk.

  • Uploading Logs to Splunk2:08

    Navigate to settings, add data, and upload the compressed log files to Splunk for your lab; follow the demo steps and upload each file individually.

  • Question: How Do Forwarders Work?2:08

    Explore how forwarders install on endpoints, configure to send Windows event logs or syslog to a Splunk server by specifying the IP address, and ensure connectivity so logs upload automatically.

  • Analyzing Uploaded Log Files11:34
  • Filtering Logs by Stats Count2:26

    Filter logs by stats count to identify top IPs with failed login attempts, view events, and investigate abnormal brute-force SSH activity across multiple ports.

  • Question: Can I have Search Parameters?1:32

    Save and index your search parameters in SIEM workflows to reuse common queries, keeping a notepad or reference index so you can quickly recall and apply them without retyping.

  • Investigating IP Addresses0:44

    Investigate suspicious IP addresses by tracing who uses each IP, how long the user has been using it, and the SSH activity, identifying brute force signs from log data.

  • Analyzing Web Application Logs9:29

    Analyze web application logs with SIEM queries to identify top client IPs, monitor HTTP status codes, and investigate potential attacks by cross-referencing IPs with VirusTotal and Hybrid Analysis.

  • Question: Malicious IP behind VPN?7:52

    Investigate whether a vpn ip is malicious by analyzing user behavior, http status codes like 503 and 404, and logs to identify attempts to drop a malicious payload.

  • Question - Function of the Visualization Tab1:51

    Explore how the visualization tab turns security data into graphical charts for quick insight and executive reports, highlighting IPs with a high rate of file not found errors.

  • Fast, Smart and Verbose Modes0:40

    Utilize three modes—fast, smart, and verbose—for SIEM searches in SOC investigations. Verbose shows all events and fields; smart offers quick searches, while fast provides balance, with no mode preference.

  • Managing Users0:50

    As an admin, create users, assign roles, and restrict permissions so departments can only view or record, handling administrative tasks alongside log analysis.

  • Question: Unveiling Masked IP Addresses3:59

    Explore how SIEM analyzes logs to reveal compromised systems and support defense in depth, while noting it cannot unmask masked IPs; rely on perimeter devices and IP verification.

Requirements

  • Curiosity and a willingness to learn about cybersecurity and log analysis

Description

Are you ready to take your cybersecurity skills to the next level? In this course "SOC Analysis with SIEM: Mastering Log Event Monitoring," you will gain practical, job-ready experience in how modern Security Operations Centers (SOCs) detect, analyze, and respond to threats using SIEM tools.

This beginner-intermediate-level course is designed for IT professionals, security enthusiasts, and anyone looking to break into the cybersecurity field. You’ll learn how to work with log data, identify suspicious activity, and use SIEM platforms to investigate security incidents. Through real-world examples and guided exercises, you'll explore how log events from various systems—such as firewalls, servers, and endpoints—can be correlated to detect and respond to attacks.

Key topics include threat detection, log event analysis, alert triage, and incident response within a SOC environment. You’ll also gain insights into industry compliance standards and how SIEM supports regulatory requirements. No prior experience with SIEM tools is required, but a basic understanding of networking and cybersecurity fundamentals will help you get the most out of this course.

Whether you're aiming to become a SOC Analyst or simply want to strengthen your threat detection skills, this course will give you a solid foundation and real-world context for using SIEM in active defense.

Who this course is for:

  • IT or cybersecurity professionals looking to transition into a SOC Analyst role
  • Students or self-taught learners with basic knowledge of networks and security concepts
  • Anyone curious about how security teams detect and investigate cyber threats