YOUR SECURITY KNOWLEDGE MAPUnderstand the source.
Understand the source.
Connect the events.
From product names to logs, fields, and investigations — a practical reference for SOC and Splunk learning.
VENDOR / PRODUCT↓LOGS / FIELDS↓DETECTION / CORRELATION
Explore:
Start here: how to read a security data source
Vendor ≠ product ≠ log type
Fortinet is a vendor. FortiGate is a product. VPN authentication and network traffic are different event types that it can produce.
Source ≠ sourcetype ≠ model
A source identifies the event origin. A sourcetype describes its format. A data model groups events by meaning using constraints and fields.
Alert ≠ confirmed compromise
Check the outcome, identity, time, and related activity. An HTTP 200, a successful login, or a high risk score alone does not confirm an attack.