Lab 22: Same Logs, New SIEM — Setting Up Splunk From Scratch
Lab 21 closed the detection gap in Elastic.
31 alerts fired. End-to-end detection confirmed. The Elastic SIEM phase of the portfolio was complete.
So naturally, I installed a second SIEM.
Lab 22 is th
blog.routetoroot.io4 min read