Knowledge / detection logging

SIEM

Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.

SIEM PIPELINECollectNormaliseCorrelateAlertIf nobody owns the queue, this is a filing cabinet.

A SIEM is a pipeline plus a queue. Logs in, detections out, humans in the middle. Volume is not coverage.

Tune until a real event is distinguishable from noise. Retire rules that have not earned their keep. Name an owner for after-hours.

If you cannot say which detections map to which ATT&CK techniques you care about, you have a data lake with a siren.