in SOC

2 Answers

by (5.9k points)
Alerts are the timely notifications which triggers when the conditions/rule in the SIEM  (Splunk) matches with the logs.
by (5k points)
Alerts depend on the type of logs pushed or pulled in Splunk. Alerts refer to notifications and we as analysts work on these depending on the criticality.

