Collect
Onboard Windows, Linux, syslog, endpoint and network telemetry with known ownership and time quality.
Build, monitor and defend modern environments using security logs, detection engineering, network visibility and practical SOC workflows.
Learn how to collect and analyze events, deploy defensive network sensors, tune detections, investigate incidents and prepare tested configurations for controlled production use.
Move from raw security telemetry to validated alerts, evidence-led investigations and controlled production readiness.
Onboard Windows, Linux, syslog, endpoint and network telemetry with known ownership and time quality.
Normalize fields, build testable rules, tune noise and validate that each detection supports a clear objective.
Correlate endpoint events, Suricata alerts and Zeek metadata into a defensible analyst timeline.
Prepare change control, rollback, health monitoring, reporting and audit-ready documentation.
Use systems you own, local virtual machines, approved sample logs and intentionally generated test events. Product sizing varies with retention, traffic volume and enabled services.
Select a learning mode, search the course, and open any lesson. Content changes instantly without reloading.
Terminology differs by platform. The operational objective remains consistent: collect trusted data, search it, create a validated detection and manage the resulting investigation.
| Operation | Wazuh | Elastic Security | Microsoft Sentinel | Splunk ES 8.4 |
|---|---|---|---|---|
| Search logs | Dashboard search / index query | Discover with KQL, ES|QL or applicable query | KQL across workspace or data-lake context | SPL |
| Create detection | Custom decoder and rule | Detection rule | Analytics rule | Detection / correlation search |
| Manage investigation | Alert workflow and integrations | Alerts, Timeline and Cases | Alerts and incidents | Findings, finding groups and investigations |
| Endpoint collection | Wazuh Agent | Fleet-managed Elastic Agent | Data connectors and supported agents | Universal Forwarder or supported integrations |
Design, validate and document a small authorized monitoring environment that connects endpoint telemetry with network evidence.
Commands and terminology in this course were checked against these primary sources. Always re-check the linked release documentation before changing a lab or production environment.
Windows agent package links, Elastic enrollment commands, Snort build dependencies, Security Onion installation choices, cloud connector menus, and licensed-platform screens are generated per tenant or release. The course therefore directs learners to the product’s current in-product command or official release guide instead of freezing fragile values.