Operate within a Security Operations Center, monitoring alerts and correlating logs to detect active threats.
Import a dataset of web server logs into an ELK stack or Splunk instance and write queries to identify a brute-force SSH attack based on failed logins.