SIEM Fundamentals
Overview
Security Information and Event Management (SIEM) platforms share common architectural patterns regardless of vendor.
Core Components
Log Collection
-
Agents - Installed on endpoints (Wazuh agent, Sentinel AMA, Splunk UF)
-
Syslog - Network devices, Linux systems
-
API Ingestion - Cloud services, SaaS applications
-
Windows Event Forwarding - Native Windows log collection
Query Language Comparison
| Platform | Language | Example (Failed Logins) |
|---|---|---|
QRadar |
AQL |
|
Sentinel |
KQL |
|
Splunk |
SPL |
|
Wazuh |
Rule XML |
|