Logstail SIEM SOAR
The Logstail SIEM SOAR helps security teams by facilitating effective log collection, threat detection, alert investigations, case management, as well as response workflow automation and response.
What you can do
The Logstail SIEM & SOAR platform allows you to:
Connect endpoints
Connect endpoints with the Logstail Agent.
Collect data
Collect logs, events, metrics, packets, and SIEM data.
Search analytics
Search and investigate logs in Analytics.
View dashboards
View dashboards with your data.
Monitor security
Monitor security agents and vulnerabilities.
Manage workflows
Manage alerts, cases, and playbooks.
Track compliance
Track governance, risk, and compliance workflows.
Recommended path
Best Practices
| Page | Description |
|---|---|
| Create an Account | Get started with your Logstail Account |
| Install an Agent | Install an agent to establish endpoint log collection and review network and telemetry data. |
| Logstail SIEM | Review endpoint activity and confirm that agents are sending data to the platform. |
| Dashboards | Monitor ingestion data and usage trends through visual dashboards. |
| Alerts | Review alerts on your SOAR and respond to to validate whether account activity and ingestion are working as expected. |
| Cases | Track investigations and confirm whether data availability supports case workflows. |