Instiq
Chapter 5 · Incident Handling·v1.0.0·Updated 7/17/2026·~14 min

What's changed: Initial version

5.1Security event monitoring and escalation

Key points

Covers the difference in roles between SIEM (collecting logs in one place and correlating them) and SOAR (automating and orchestrating the response after detection), the targets of network data monitoring such as packet capture and various logs, and how to identify a suspicious event ("this is not normal") and judge when to escalate, as the entry point to monitoring.

Incident handling begins, before any dramatic response, with the machinery of noticing. Finding "this is not normal" among a flood of logs and traffic and, when needed, handing it up—this first checkpoint is monitoring and escalation. This section covers the difference in roles between SIEM (collecting logs in one place and correlating them) and SOAR (automating the response after detection), the targets of network data monitoring such as packet capture and various logs, and how to identify a suspicious event and when to escalate—learned not by rote but through the lens of "what does this sign on this screen mean."

5.1.1The differing roles of SIEM and SOAR

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.