SIEM-Security-Information-and-Event-Management

Security Monitoring and Logging using SIEM

Step 1: If you didn’t choose to start Splunk during the installation, start it manually by navigating to ‘C:\Program Files\Splunk\bin’ and running ‘splunk.exe start’.

Screenshot1

Step 2: Open Splunk Web:

Screenshot2

Step 3: Configure Splunk:

Screenshot3

Step 4: Install Necessary Splunk Apps for SIEM

Screenshot4

Screenshot5

Screenshot6

Screenshot7

Step 5: After installing the apps, restart Splunk to apply the changes. Go to ‘Settings > Server controls > Restart Splunk’.

Screenshot8

Screenshot9

Step 6: Configure Windows Event Logs:

Screenshot10

Screenshot11

Step 7: Configure Windows Performance Monitoring:

Processor

Screenshot12

Screenshot13

Memory

Screenshot14

Network

Screenshot15

Step 8: Verify Data Ingestion Search for Data:

Screenshot16

Step 9: Check for Errors:

Screenshot17

Screenshot18

Step 10: Create Alerts & Generate Report:

Screenshot19

Go to Activity > Triggered Alerts

Screenshot20

Generated Report for Event ID 4625

Screenshot21

Exported Report as PDF

Screenshot22

Step 11: Create Dashboards:

Screenshot23

Query: index=”main”

Screenshot24