Skip to content
FirstSIDocs

SIEM: correlation and security incidents

The rules that cross-check events from the modules, an incident's life cycle, response times (SLA) and notifications.

Every 30 seconds the SIEM reads the events from the other modules (files, flows, availability, network, DNS, authentication, firewall, Microsoft 365) and runs them through its correlation rules. When a rule fires, it opens an incident numbered INC-year-number.

The security incident list, with filters and deadline tracking (demo data).
The security incident list, with filters and deadline tracking (demo data).

Getting started: install, then turn on the rules

In Correlation rules (#/siem/rules), Install default rules adds 58 rules: security, infrastructure, compliance, Active Directory, Microsoft 365. They all arrive switched off. Turn on the ones that match your modules with the switch in the Status column, starting with the critical ones.

Customise adjusts a rule for your organization only; Reset to default goes back to the original version. A rule has a time window, a repeat delay (at least 60 s), a priority (1 to 100) and conditions joined by AND or OR. Of its actions, only "send notification" is actually carried out; the others (isolate, block…) appear in the incident as recommendations.

Handling an incident

Security Incidents (#/siem/incidents) can be filtered by status, severity, category, dates and text (title, number or description). Export produces the list as CSV or PDF. A banner flags incidents that are past their deadline.

Life cycle
Open → Acknowledged → Investigating → Resolved → Closed

While an incident is Open, new events from the same rule and the same entities are added to it instead of opening another incident. The incident page shows Affected Entities, Recommended Actions, the Event Timeline and the Action History (who acknowledged, who resolved).

To resolve an incident you have to classify it: True positive - Threat confirmed, False positive, Threat mitigated or No action required, with notes if needed.

Response times (SLA)

SeverityAcknowledge withinResolve within
Critical5 min60 min
High15 min4 h
Medium60 min8 h
Low4 h24 h

Past that delay, the incident is marked Breached and escalated.

Notifications

In SIEM Notifications: Enable notifications (off by default), Severity threshold (Critical by default), the Event types (creation, escalation, resolution) and the Notification channels, which are the HostMonitor ones (e-mail, Slack, Teams, Discord, Telegram, webhook, SMS). Send a test checks the whole chain.

Rights

ActionRoles
View, exporteveryone
Move an incident forward, test notificationsoperator, administrator
Rules, notificationsadministrator

Frequently asked questions

No e-mails. Notifications are off by default, the threshold is set to Critical, and at least one channel must be ticked.

Why one incident for so many events? That is the grouping at work: an open incident absorbs the rest of the same attack.

Source: · FirstSI Docs · updated 2026-10-10