How to write a use cases for any network devices

Hi All,

Please help us, how to write the use cases for Network devices in SIEM.

Please share with me if have any example use cases format and we are not ware up on how to write the use cases.

thanks!

Solved Solved
0 2 86
1 ACCEPTED SOLUTION

Thanks for the sharing links, now got it, how to write the use cases.

View solution in original post

2 REPLIES 2

This is extremely broad and I'm not certain where you are looking to start. I would point out that @tameri posted a nice reference on using Zeek with search last week https://www.googlecloudcommunity.com/gc/SIEM-Forum/Chronicle-Search-Zeek-A-Quick-Reference/m-p/72355... and we maintain a community rule set https://github.com/chronicle/detection-rules that contains examples that could be used as a starting point.

Thanks for the sharing links, now got it, how to write the use cases.