Round 1 - Design a SIEM system
Anónimo
Discussed the following * Using an RDBMS or NoSQL data store * Agent based log collection design * Filtering on agent side to prevent spamming by setting thresholds like data per sec sent out * Filtering for analysis on user end * Building an analytics dashboard * Storage for archival * Backups * Rules for monitoring and alerting * Deploying DLP