SXMonitorDocs

SXMonitor User Guide

Product documentation for the SXMonitor defensive security platform.

SXMonitor ingests raw logs from your cloud platforms, normalises them, runs detection against them, and delivers prioritised alerts to the places your team already works. This guide covers every module in the platform, from connecting your first log source to configuring tenant-level access control.

Start here

The platform, module by module

AreaModuleWhat it covers
CoreLog SourceRegistering the data sources that feed events into SXMonitor
Security OperationsThreat HuntingSearching, filtering, and exporting normalised events
Security OperationsMITRE ATT&CK CoverageA heatmap of detection coverage across 222 techniques
Security OperationsCustom ChartsBuilding visualisations of alert and log data
DetectionDetection RulesThe Sigma rule library — rules are assigned to matching log sources automatically
DetectionSigma Rule ConverterWriting Sigma YAML and converting it to KQL
AlertingAlert DashboardTriaging alerts fired by your detection rules
AlertingNotification ChannelsDelivering alerts to Slack, Google Chat, and custom webhooks
AdministrationUser ManagementCreating organisation users and assigning roles
AdministrationTenant ManagementSegmenting your organisation into tenants
AdministrationRole ManagementDefining what each role can do per module
AdministrationTenant User ManagementGranting users access to a specific tenant

Suggested reading order

If you are setting SXMonitor up for the first time, work through it in this order — each step depends on the one before it:

  1. Tenant Management — create your environments
  2. Role Management — define permissions
  3. User Management — create organisation users
  4. Tenant User Management — assign users to tenants
  5. Log Source — connect your data
  6. Detection Rules — rules are assigned to your sources automatically; review your coverage
  7. Notification Channels — decide where alerts land