> For the complete documentation index, see [llms.txt](https://notes.nomanaziz.me/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.nomanaziz.me/cybersecurity/blue-teaming/intrusion-detection/security-event-monitoring.md).

# Security Event Monitoring

### Splunk

* Used to analyze data and logs produced by systems
* Provide us with robust visualization and reporting tools

#### Forwarding Snort Logs to Splunk

We can forward snort logs to splunk to visualize them. We will use `splunk universal forwarder` tool installed on snort server

***
