Skip to content

Security monitoring basics: logs, detections and triage

What a SIEM does whatever the product: choosing log sources, collecting and normalizing them, keeping time consistent, retention and integrity, searching around an entity, how detections work and how to tune them with evidence, and how to triage, document and escalate an alert.

Level
Beginner
Length
About 45 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026

Skills you'll practise

  • Choose which log sources to collect first and explain why
  • Explain normalization, time synchronization and retention, and spot a time-zone mistake in a timeline
  • Recognize a log source that has stopped sending and treat it as an issue
  • Distinguish threshold, correlation and anomaly detections, and tune a noisy rule with a narrow, documented exception
  • Triage an alert: validate, scope, enrich, decide and document, escalating per the playbook

Course outline

  1. 1.Security monitoring basicsVideo · 2 min
  2. 2.Logs worth collectingLesson · 15 min
  3. 3.Searching and detectionsLesson · 15 min
  4. 4.Triage, documentation and escalationLesson · 15 min
  5. 5.Security monitoring basics: logs, detections and triage: knowledge checkKnowledge check · 16 questions
  6. 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.