SXMonitor User Guide
Product documentation for the SXMonitor defensive security platform.
SXMonitor ingests raw logs from your cloud platforms, normalises them, runs detection against them, and delivers prioritised alerts to the places your team already works. This guide covers every module in the platform, from connecting your first log source to configuring tenant-level access control.
Start here
- Product overview — what SXMonitor does and who it is for
- Sign up — create an account and get it approved
- Sign in — access the platform
The platform, module by module
| Area | Module | What it covers |
|---|---|---|
| Core | Log Source | Registering the data sources that feed events into SXMonitor |
| Security Operations | Threat Hunting | Searching, filtering, and exporting normalised events |
| Security Operations | MITRE ATT&CK Coverage | A heatmap of detection coverage across 222 techniques |
| Security Operations | Custom Charts | Building visualisations of alert and log data |
| Detection | Detection Rules | The Sigma rule library — rules are assigned to matching log sources automatically |
| Detection | Sigma Rule Converter | Writing Sigma YAML and converting it to KQL |
| Alerting | Alert Dashboard | Triaging alerts fired by your detection rules |
| Alerting | Notification Channels | Delivering alerts to Slack, Google Chat, and custom webhooks |
| Administration | User Management | Creating organisation users and assigning roles |
| Administration | Tenant Management | Segmenting your organisation into tenants |
| Administration | Role Management | Defining what each role can do per module |
| Administration | Tenant User Management | Granting users access to a specific tenant |
Suggested reading order
If you are setting SXMonitor up for the first time, work through it in this order — each step depends on the one before it:
- Tenant Management — create your environments
- Role Management — define permissions
- User Management — create organisation users
- Tenant User Management — assign users to tenants
- Log Source — connect your data
- Detection Rules — rules are assigned to your sources automatically; review your coverage
- Notification Channels — decide where alerts land