◈ SOC ATLASSecurity data source guide
LEARN · MAP · CORRELATE
YOUR SECURITY KNOWLEDGE MAP

Understand the source.
Connect the events.

From product names to logs, fields, and investigations — a practical reference for SOC and Splunk learning.

VENDOR / PRODUCT↓LOGS / FIELDS↓DETECTION / CORRELATION
Start here: how to read a security data source
01 · IDENTIFY

Vendor ≠ product ≠ log type

Fortinet is a vendor. FortiGate is a product. VPN authentication and network traffic are different event types that it can produce.

02 · NORMALIZE

Source ≠ sourcetype ≠ model

A source identifies the event origin. A sourcetype describes its format. A data model groups events by meaning using constraints and fields.

03 · INVESTIGATE

Alert ≠ confirmed compromise

Check the outcome, identity, time, and related activity. An HTTP 200, a successful login, or a high risk score alone does not confirm an attack.