Another Friday SIEM post, hot off the blog stove. Almost as hot as the heat wave cooking Europe right now. ☀️
This week: SIEM onboarding
Most SIEM projects don't fail on technology. They fail on planning.
Connect as many systems as possible. Ingest whatever logs you can. Switch on a pile of detections. Then burn the next few months tuning.
The irony is that almost every project kicks off with a detailed implementation plan. Then reality hits. Timelines slip, priorities shift, and the team drifts right back into this reactive loop.
Start with threat assessment and threat modeling.
Know who you're defending against and which techniques actually matter in your environment.
From there:
Build your detection strategy.
Identify the data those detections require.
Then, and only then, decide what logs belong in the SIEM.
Threat intel informs detections. Detections inform data. In that order.
Having the right data and structure together with Detection engineering is the foundation.
Get it right and everything downstream gets easier. Get it wrong and you'll spend months chasing false positives, hoarding data you don't need, and tuning rules that should never have existed.
There are solid tools now for detection engineering, attack mapping, and validation.
Not everything is a crown jewel. If every system is business critical, none of them are.
Rafał Kitab Kitab wrote the definitive version of this, built on 30+ SIEM onboarding projects. He breaks the work into three 30-day phases (centralize and learn, build detections, protect crown jewels) and makes the case for why threat intel drives the whole thing.
I won't ask the question, but I know you will be tempted to share a story, or maybe not 😃
Originally posted on LinkedIn on 26 June 2026.
Read the original post and the comments.


