Optimalizace a rozšíření vybrané SIEM platformy v kontextu současných bezpečnostních výzev

Abstract

This thesis examines the use of SIEM (Security Information and Event Management) systems in a production environment. It compares selected open source SIEM solutions using predefined criteria and following this comparison, a specific platform is selected, and areas for further investigation are subsequently identified. Based on the results of this analysis, new features are designed and implemented to further enhance the selected platform. The thesis also includes an evaluation of the benefits of deploying this solution. Both the design and implementation are carried out in accordance with current security standards, particularly the NIS2 Directive.

Description

Delayed publication

Available after

Subject(s)

SIEM, log management, NIS2, Wazuh, incident detection, infrastructure monitoring, decoders, detection rules, AI chatbot, security dashboards

Citation