Splunk-Based SIEM for Real-Time Threat Detection

  • Unique Paper ID: 205647
  • Volume: 13
  • Issue: 1
  • PageNo: 8592-8601
  • Abstract:
  • The rapid increase in cyber threats has highlighted the need for effective Security Information and Event Management (SIEM) solutions capable of detecting and responding to security incidents in real time. Traditional security monitoring methods often struggle to analyze large volumes of log data generated by enterprise systems, resulting in delayed threat identification and increased security risks. This paper presents a Splunk-Based SIEM for Real-Time Threat Detection, designed to provide centralized log collection, real-time event correlation, and automated alert generation in a Windows Server environment. The proposed framework utilizes Splunk Enterprise 10.0 to collect and analyze Sysmon logs from multiple virtual machines, enabling comprehensive monitoring of authentication events and system activities. Custom Search Processing Language (SPL) correlation rules are implemented to identify brute-force authentication attacks by detecting repeated failed login attempts and suspicious user behavior. Upon detecting malicious activity, the system generates real-time alerts and interactive dashboards to support rapid investigation and incident response by Security Operations Center (SOC) analysts. The framework is further enhanced by mapping detected attack techniques to the MITRE ATT&CK framework, providing standardized threat classification and improving security analysis. Experimental evaluation demonstrates efficient log ingestion, fast search execution, and timely alert generation, confirming the effectiveness of the proposed approach for enterprise security monitoring. The results show that the developed SIEM framework enhances threat visibility, reduces incident response time, and provides a scalable solution for real-time cybersecurity operations.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{205647,
        author = {Syed Omair and Subramanian k. M and Md. Ateeq Ur Rahman},
        title = {Splunk-Based SIEM for Real-Time Threat Detection},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {1},
        pages = {8592-8601},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=205647},
        abstract = {The rapid increase in cyber threats has highlighted the need for effective Security Information and Event Management (SIEM) solutions capable of detecting and responding to security incidents in real time. Traditional security monitoring methods often struggle to analyze large volumes of log data generated by enterprise systems, resulting in delayed threat identification and increased security risks. This paper presents a Splunk-Based SIEM for Real-Time Threat Detection, designed to provide centralized log collection, real-time event correlation, and automated alert generation in a Windows Server environment. The proposed framework utilizes Splunk Enterprise 10.0 to collect and analyze Sysmon logs from multiple virtual machines, enabling comprehensive monitoring of authentication events and system activities. Custom Search Processing Language (SPL) correlation rules are implemented to identify brute-force authentication attacks by detecting repeated failed login attempts and suspicious user behavior. Upon detecting malicious activity, the system generates real-time alerts and interactive dashboards to support rapid investigation and incident response by Security Operations Center (SOC) analysts. 
The framework is further enhanced by mapping detected attack techniques to the MITRE ATT&CK framework, providing standardized threat classification and improving security analysis. Experimental evaluation demonstrates efficient log ingestion, fast search execution, and timely alert generation, confirming the effectiveness of the proposed approach for enterprise security monitoring. The results show that the developed SIEM framework enhances threat visibility, reduces incident response time, and provides a scalable solution for real-time cybersecurity operations.},
        keywords = {Security Information and Event Management (SIEM), Splunk Enterprise 10.0, Sysmon, Windows Server, Threat Detection, Security Monitoring, Search Processing Language (SPL), Brute-Force Attack, Authentication Monitoring, MITRE ATT&CK},
        month = {June},
        }

Cite This Article

Omair, S., & M, S. K., & Rahman, M. A. U. (2026). Splunk-Based SIEM for Real-Time Threat Detection. International Journal of Innovative Research in Technology (IJIRT), 13(1), 8592–8601.

Related Articles