Talk With an Expert

Creating Your Own SIEM and Incident Response Toolkit Using Open Source Tools

Creating Your Own SIEM and Incident Response Toolkit Using Open Source Tools (PDF, 1.70MB)Published: 28 Jun, 2011
Created by
Jonny Sweeny

This paper describes how one can use open source tools to create an incident response toolkit. A significant piece of your toolkit is a Security Information and Event Manager (SIEM), or the ability to store and process event logs. Two reasons you may want to create your own toolkit and SIEM are: financial and the ability to customize. In addition to outlining what software tools you should have in your kit and how to create them, I will explain how to prioritize your efforts in creating the toolkit. This paper could easily be used to guide in the selection of a commercial SIEM.