Lab 12: How I Taught My SIEM to Recognize an Attack
Lab 11 got the pipeline running. Logs were flowing from my Kali Linux host into Elastic SIEM. The agent was enrolled. The data was real. But a SIEM that ingests logs and does nothing with them is just





