SynRAG: A Large Language Model Framework for Executable Query Generation in Heterogeneous SIEM System
Md Hasan Saju, Austin Page, Akramul Azim, Jeff Gardiner, Farzaneh Abazari, Frank Eargle

TL;DR
SynRAG is a framework that automatically generates platform-specific SIEM queries from high-level specifications, enabling effective cross-platform threat detection and incident investigation in heterogeneous enterprise environments.
Contribution
We introduce SynRAG, a novel framework that translates platform-agnostic specifications into specific SIEM queries, improving cross-platform security operations and reducing manual effort.
Findings
SynRAG outperforms existing language models in generating effective SIEM queries.
It enables seamless threat detection across diverse SIEM platforms.
The framework reduces the need for extensive training on multiple SIEM systems.
Abstract
Security Information and Event Management (SIEM) systems are essential for large enterprises to monitor their IT infrastructure by ingesting and analyzing millions of logs and events daily. Security Operations Center (SOC) analysts are tasked with monitoring and analyzing this vast data to identify potential threats and take preventive actions to protect enterprise assets. However, the diversity among SIEM platforms, such as Palo Alto Networks Qradar, Google SecOps, Splunk, Microsoft Sentinel and the Elastic Stack, poses significant challenges. As these systems differ in attributes, architecture, and query languages, making it difficult for analysts to effectively monitor multiple platforms without undergoing extensive training or forcing enterprises to expand their workforce. To address this issue, we introduce SynRAG, a unified framework that automatically generates threat detection…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware System Performance and Reliability · Information and Cyber Security · Network Security and Intrusion Detection
