4 Comments
User's avatar
Jonathan Bourke's avatar

Great post Andrea. Now I need to go link it to Sentinel tables & rules!

Brodie Cassell's avatar

Thank you for writing this up, Andrea!

Dhani Abey's avatar

I get this question with every new SIEM conversation. Thanks for writing this up Andrea!

Kevin's avatar

Depends on organization and setup but I believe all critical network/security devices and servers should be addressed.