March 28, 2024, 4:38 p.m. | /u/Aleduc_

cybersecurity www.reddit.com

Hi all,

My management has decided that the SOC (me) should monitor WAF alerts in our SIEM (?). I just don't see the point or what can be done:

\- either the traffic has been blocked by the WAF and then no action is required

\- either the traffic went through, and if it is illegitimate, that means the WAF needs improvement, so then no monitoring action to take

Am I missing something?

action alerts blocked can cybersecurity don management monitor point siem soc traffic waf

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Consultant Sécurité SI Gouvernance - Risques - Conformité H/F - Strasbourg

@ Hifield | Strasbourg, France

Lead Security Specialist

@ KBR, Inc. | USA, Dallas, 8121 Lemmon Ave, Suite 550, Texas

Consultant SOC / CERT H/F

@ Hifield | Sèvres, France