CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· Data Flow

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • Logs are collected from endpoints, network, cloud and apps
  • Parsing and enrichment add user, asset and threat context
  • Detections create alerts and cases for SOC analysts

Prompt used

Data flow for a SIEM pipeline: endpoint EDR, firewalls, identity provider, cloud audit logs and application logs are collected by agents and syslog forwarders into a log pipeline, parsed into a common schema, enriched with asset inventory, user directory and threat intelligence (IP/domain reputation), stored in hot and cold storage, evaluated by detection rules and UEBA, and alerts create cases for SOC analysts in the SOAR platform.

Mermaid code
flowchart LR
  EDR[Endpoint EDR] --> COL[Collectors and syslog]
  FW[Firewalls] --> COL
  IDP[Identity Provider] --> COL
  CLOUD[Cloud audit logs] --> COL
  APP[Application logs] --> COL
  COL --> PARSE[Parse to common schema]
  PARSE --> ENR[Enrichment]
  ASSET[(Asset inventory)] --> ENR
  DIR[(User directory)] --> ENR
  TI[(Threat intelligence)] --> ENR
  ENR --> HOT[(Hot storage - 30 days)]
  HOT --> COLD[(Cold storage - 1 year)]
  HOT --> DET[Detection rules and UEBA]
  DET -->|Alerts| SOAR[SOAR case management]
  SOAR --> SOC[SOC Analysts]

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.

State MachineCybersecurity

Vulnerability Management Lifecycle

The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.