A quick introduction to the terminology
During this chapter, we will be using the terms feeds and alerts very frequently. We want to ensure that you have a full understanding of the differences and the use cases. What is a feed? What is an alert? Let's get right into this!
Feed
A feed is a constant stream of activity that has been configured for ingestion or analysis. This activity is used for statistical purposes, and sometimes this is referred to as an audit trail or log/logging:
- Example: A record of each time a door opens and closes. This would be an audit of how many times and each time the door was opened or shut.
Alert
An alert is a notification generated in response to an event or a sequence of events that is characteristic of suspicious behavior. The alert is intended to bring the event(s) to the attention of an operator or a Security Operations Center (SOC) analyst:
- Example: Whenever that same door is slammed opened or slammed shut, an...