Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
An organization uses a Security Information and Event Management (SIEM) system to aggregate and analyze security logs. Recently, a new application was deployed that generates a high volume of legitimate, but verbose, log entries. This has led to a significant increase in SIEM storage consumption and processing load, causing some critical alerts to be delayed. What SIEM optimization technique should be applied first to address this issue?
- AImplement log filtering and aggregation at the source.
- BIncrease SIEM server resources (CPU, RAM, storage).
- CTune SIEM correlation rules to be more specific.
- DDeploy additional SIEM forwarders to distribute the load.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement log filtering and aggregation at the source.
The problem states that too much 'legitimate, but verbose' log data is causing issues. Implementing log filtering and aggregation at the source (e.g., on the application host or a log collector) reduces the volume of data sent to the SIEM, directly addressing storage and processing load without losing critical information.
Why the other options are wrong
- B. Increasing resources is a reactive and potentially costly solution without first optimizing log data.
- C. Tuning correlation rules helps with alert quality, but doesn't reduce the raw data volume overwhelming the SIEM.
- D. Deploying more forwarders might distribute collection, but doesn't reduce the total volume of data being ingested and processed by the SIEM backend.
Log Filtering/Aggregation
The process of reducing the volume of log data by removing irrelevant entries or combining similar entries before they are ingested by a SIEM.
- Done at the log source or an intermediate collector.
- Improves SIEM performance and reduces storage costs.
- Ensures only relevant data is processed for security analysis.
Memory trick: To make SIEM swift and smart, filter early, play your part!