DemandFlow Support Centre

SIEM
9 articles
No articles match your search.

SIEM

SIEM: Overview

Reference
A short tour of DemandFlow's SIEM: what it does, how the pieces fit together and a typical workflow from first log i...
Updated 16/04/2026

Setting up a log source and generating an ingest key

Procedure
How an admin creates a log source record and generates its one-time ingest API key so an external system can start sendi...
Updated 17/04/2026

Ingesting logs via the API

How-To
The wire contract for sending log events to DemandFlow: endpoint, headers, body format, limits, and example requests in ...
Updated 17/04/2026

Using the Log Viewer

How-To
A complete guide to the DemandFlow SIEM Log Viewer. Covers time ranges, source and severity facets, full-text search syn...
Updated 17/04/2026

Monitoring source health

How-To
How to use the Source Health screen to monitor log source connectivity, detect silent sources, configure heartbeat inter...
Updated 17/04/2026

Writing alert rules

How-To
How to create an alert rule so log events turn into actionable alerts. Covers the three rule types, scoping, cooldown an...
Updated 17/04/2026

Triaging alerts

How-To
How to work through alerts: the triage states, how to investigate using sample events, and how to close alerts as resolv...
Updated 16/04/2026

SIEM dashboards and the dashboard designer

How-To
Build and view SIEM dashboards that summarise log volume, source health, alerts and trends.
Updated 16/04/2026

Using integration flows for SIEM notifications

How-To
How to build an integration flow that dispatches alerts to Slack or email, webhooks or anywhere else, and wire it to you...
Updated 16/04/2026