What is Event life cycle ?

1 Answer

Steps in Event life cycle:

  • Threat Detection: checking whether the event is an Incident.
  • Translation: Raw data from log sources are translated into common format and interpreted in SIEM.
  • Prioritization: Prioritising the Events based on criticality.
  • Escalation: sending alerts to concerned team.
  • Analysis: event analysis, creation of report and documentation.
  • Compliance: retention policies, rules and procedures can be followed easily.

