Data Sources, Dashboards, and Reports
Summary
PDF p.315In incident response and digital forensics, data sources are analyzed to discover indicators. SIEM tools aggregate and correlate these diverse data sources, providing dashboards and automated reports to support incident management.
In plain words
Supplementary — not from your PDFInvestigations draw on many data sources: memory and file system data, network appliance logs, traffic captures, vulnerability scan logs, OS and application logs, and endpoint security logs. The challenge is the 'Vs': volume, velocity, variety, veracity and value. A SIEM brings them together, with dashboards for daily monitoring (different ones for analysts and managers) and automated reports (alerts that open cases, and status reports).
Detailed explanation
PDF p.315Data Sources
- System Memory and Media Device Data: Includes file system data and metadata.
- Network Appliance Logs: Generated by switches, routers, and firewalls/UTMs.
- Network Traffic: Captured by sensors and intrusion detection systems.
- Vulnerability Scanner Logs: Generated by network-based scanners.
- OS Component Logs: From client and server host computers.
- Application and Service Logs: From hosts.
- Endpoint Security Logs: Includes host-based intrusion detection, vulnerability scanning, antivirus, and firewall security software.
Challenges
- Diversity and Size: Managing large and varied data sources.
- "Vs" of Data: Volume, velocity, variety, veracity, and value.
Dashboards
- Purpose: Provide a console for day-to-day incident response.
- Customization: Separate dashboards for different purposes (e.g., incident handler vs. manager).
- Content: Visualizations (graphs, tables) showing key status metrics.
Automated Reports
-
Types
- Alerts and Alarms: Detect threat indicators and start incident cases.
- Status Reports: Communicate threat levels, incident numbers, and effectiveness of controls.
- Customization: Preconfigured and custom reports tailored to audience needs.
Important terms
taken from the text above- System Memory and Media Device Data
- Includes file system data and metadata.
- Network Appliance Logs
- Generated by switches, routers, and firewalls/UTMs.
- Network Traffic
- Captured by sensors and intrusion detection systems.
- Vulnerability Scanner Logs
- Generated by network-based scanners.
- OS Component Logs
- From client and server host computers.
- Application and Service Logs
- From hosts.
- Endpoint Security Logs
- Includes host-based intrusion detection, vulnerability scanning, antivirus, and firewall security software.
- Diversity and Size
- Managing large and varied data sources.
- "Vs" of Data
- Volume, velocity, variety, veracity, and value.
- Customization
- Separate dashboards for different purposes (e.g., incident handler vs. manager).
- Alerts and Alarms
- Detect threat indicators and start incident cases.
- Status Reports
- Communicate threat levels, incident numbers, and effectiveness of controls.
Examples & real-world scenarios
Supplementary — not from your PDF- An analyst dashboard showing open alerts.
- A manager dashboard showing incident trends.
- A weekly automated status report.
Scenario
A manager wants a monthly view of incident counts and control effectiveness without digging into raw logs. An automated status report from the SIEM provides it.
Common mistakes
Supplementary — not from your PDF- Giving everyone the same dashboard regardless of role.
- Collecting everything without thinking about value.
Practical skills
Supplementary — not from your PDF- Design dashboards for an analyst and a manager.
What I should remember
Key Points PDF p.315-
Data Sources
- System Memory and Media Data: File system data and metadata.
- Network Appliance Logs: Switches, routers, firewalls.
- Network Traffic: Sensors and IDS.
- Vulnerability Scanner Logs: Network-based scanners.
- OS Component Logs: Client and server hosts.
- Application and Service Logs: Hosts.
- Endpoint Security Logs: Intrusion detection, antivirus, firewall.
-
Challenges
- Diversity and Size: Managing large data sources.
- "Vs" of Data: Volume, velocity, variety, veracity, value.
-
Dashboards
- Purpose: Incident response console.
- Customization: Different dashboards for different roles.
- Content: Key status metrics.
-
Automated Reports
- Types: Alerts/alarms and status reports.
- Customization: Preconfigured and custom reports.