A real attack is not a single moment but a chain. Lockheed Martin formulated it as the Cyber Kill Chain: if one link is stopped — the entire chain is broken. Click on a stage in the diagram to see what happens in it and what is actually seen from it.
Why do we even need SIEM?
On the left are the log sources: a domain controller, workstations running Sysmon, network gear sending syslog and Linux servers. An agent or forwarder collects, parses and ships the logs to a central server, where they are normalised and indexed, correlation rules run (twenty 4625 events in a minute raise an alert) and a dashboard or alert reaches the analyst. That is why admins configure the endpoints while analysts work on a central log server: one timeline, cross-host correlation, and logs that survive a wiped machine.
- One timeline: Event 4625 on the workstation and a Firewall event from the same second appear together on the same screen.
- Correlation between computers: the same account failed on ten workstations in a minute — this is one rule in , and without it, no one would notice.
- Survivability: If the attacker deleted the local log (Event 1102), the copy on the central server has already been sent.
- History: You can go back months when a new IOC is discovered.
- Common tools: Wazuh (free, ELK-based), Splunk (enterprise), Elastic Security, Microsoft Sentinel.