Logstail SIEM SOAR
Collect telemetry, investigate events, manage alerts, open cases, automate response, and report on security operations.
Logstail Documentation
Use Logstail to collect telemetry, monitor infrastructure, triage alerts, automate response, manage external exposure, enrich investigations with threat intelligence, and train teams with hands-on cybersecurity workflows.
Pick the Logstail module that matches the workflow you are building.
Collect telemetry, investigate events, manage alerts, open cases, automate response, and report on security operations.
Discover public-facing assets, scan authorized targets, review exposure findings, and export technical or executive reports.
Onboard analysts, build practical cyber skills, complete structured learning paths, and practice with hands-on labs.
Role-based paths that map real security operations work to the right docs.
Start with telemetry collection, search suspicious activity in Analytics, prioritize SOAR alerts, and turn validated alerts into cases.
Use cases for investigation tracking, playbooks for repeatable response, integrations for enrichment and action, and notification channels for escalation.
Use Discover, Insights, dashboards, and CTI observables to move from raw event data to validated threat context.
Run authorized EASM scans against domains, subdomains, public IPs, URLs, web apps, and external services, then review findings and reports.
Use compliance views, reports, dashboards, account data, and EASM evidence to support audit preparation and stakeholder communication.
Use agent inventory, SNMP monitoring, pre-built dashboards, and saved objects to keep monitoring coverage operational.
Administer access, profile preferences, SOAR runners, integration credentials, CTI settings, and account-level details.
Use Logstail Academy to onboard SOC analysts, standardize security operations training, and practice attacker and defender workflows.
Not sure where to start? Jump straight into the highest-signal docs.