SOC Analyst Simulation

Run a shift on Raqib, a SIEM modeled on Splunk Enterprise Security and IBM QRadar. Search the live logs yourself with a query language, triage the offenses the correlation engine raised, investigate each on its own timeline, and take only the response actions that fit that alert. Every control does something: playbooks run as checklists, the dashboard reflects the live data, and your shift report is generated from what you actually did.

0open
0critical
0score
00:00:00

Query language: field=value, field!=value, wildcards host=FIN-*, and pipes | stats count by source, | timechart, | sort -time. Click any event for full detail.

Results: 0 eventslast 4 hours

Offenses

0 open
0
events ingested
0
open offenses
0
offenses closed

Event volume over time (15-minute buckets)

Events by severity

Events by source

Response playbooks

Shift reporting