This Author published in this journals
All Journal Jurnal Krisnadana
I Gede Adnyana Adnyana
Institut Bisnis dan Teknologi Indonesia, Denpasar, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

SOC Implementation for Cybersecurity Incident Handling Optimization I Gede Adnyana Adnyana; I Nyoman Buda Hartawan Hartawan; I Nyoman Arnawan; Mahesa Rama Aditya
Jurnal Krisnadana Vol 5 No 3 (2026): Jurnal Krisnadana May - July 2026
Publisher : Yayasan Sinergi Widya Nusantara (Sidyanusa)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.58982/kjvrk872

Abstract

Cybersecurity incidents continue to increase in complexity and impact, requiring institutions to improve their monitoring and response capabilities. This study implements a simple Security Operations Center (SOC) workflow to support cybersecurity incident handling through endpoint monitoring, alert generation, workflow automation, and real-time notification. The system integrates Wazuh as a Security Information and Event Management platform, Wazuh Agent as an endpoint log collector, n8n as a workflow automation tool, and Telegram as a notification channel. The implementation was carried out by deploying the required services using Docker, registering monitored endpoints through Wazuh Agent, configuring Wazuh alerts, forwarding alerts to n8n through webhook integration, parsing important alert fields, and sending structured notifications to administrators through Telegram. The system was evaluated through several test scenarios, including agent connectivity, failed SSH login detection, malware detection, Wazuh-to-n8n alert delivery, alert parsing, and Telegram notification delivery. The results show that the implemented SOC workflow successfully receives endpoint logs, generates security alerts, processes alert data automatically, and sends real-time notifications to administrators. This implementation demonstrates that open-source tools can be integrated to build a practical SOC workflow for improving initial cybersecurity incident awareness and response.