Splunk, one of the most well-known security incident and event management tools, produced a 2018 white paper on moving incident and event management away from just data collating to data analysis, which is available at https://www.splunk.com/pdfs/white-papers/the-seven-essential-capabilities-of-analytics-driven-siem.pdf.
- The manual pages for the Unix CLI commands listed can be found as follows:
- A good resource on the normal forms can be found at https://www.guru99.com/database-normalization.html.
- A good article by SS8 COO Faizel Lakhani to the commission on enhancing national cybersecurity on retrospective analysis can be found at https://www.nist.gov/sites/default/files/documents/2016/09/16/ss8_rfi_response.pdf.