Help Center/ SecMaster/ Service Overview/ Basic Concepts/ What Is Security Analysis?
Updated on 2026-07-01 GMT+08:00

What Is Security Analysis?

Security analysis is a cloud native Security Information and Event Management (SIEM) solution that identifies and evaluates potential threats and vulnerabilities in systems, software, and networks. It aggregates security logs and alerts from multiple cloud products and analyzes them using out-of-the-box and custom security rules. This enables proactive threat detection, mitigates security risks, protects assets, ensures service continuity, and reinforces customer trust.

Why Do We Need Security Analysis?

In today's digital landscape, organizations increasingly rely on sophisticated IT systems to store and process sensitive data. However, these systems are vulnerable to a wide range of security threats, both internal and external, such as hacking attacks, data breaches, and internal operational errors. Although many organizations have implemented foundational security controls, rapidly evolving threats frequently outpace traditional defenses. For example, frequent ransomware attacks and data breaches have caused significant economic losses and reputational damage to businesses. How do organizations effectively identify and respond to these evolving security threats to keep their system security and reliability? The answer lies in periodic security analysis. This enables organizations to systematically identify potential security vulnerabilities and threats, assess their impact, and take preventive measures. Beyond reducing the frequency of security incidents, periodic security analysis helps ensure regulatory compliance, strengthens customer trust, and protects critical assets.

What Are the Advantages of Security Analysis?

  • Comprehensive: Identifies potential threats at the network, application, and data layers.
  • Automatic: Leverages automated threat detection to analyze high-volume security data efficiently, requiring little to no manual intervention.
  • Real-time: Monitors your system status in real time to detect potential threats promptly.
  • Customizable: Supports custom check rules of log alert models to meet your specific requirements and service scenarios.
  • Regulatory compliance: Helps with compliance with various security and privacy regulations.
  • Observable: Provides log audit reports, helping management and security teams clearly understand the security status and develop effective countermeasures in a timely manner.

What Are Application Scenarios of Security Analysis?

To use all security analysis functions, SecMaster professional edition supports is recommended. SecMaster standard edition supports some of security analysis functions. For details about differences between service editions, see Edition Differences.

Typical scenario 1: log audit

Regulatory oversight in security is intensifying, with escalating compliance demands. The proliferation of complex privacy, data security, and cybersecurity regulations poses significant compliance challenges for enterprises. SecMaster provides baseline inspection, log audit, and security analysis to help enterprises comply with national and industry regulations, clarify security objectives, establish a systematic framework for information system security, and mitigate security and attack risks.

Typical scenario 2: threat detection and response

Cloud threats can compromise enterprise assets through various attack vectors, including network and host intrusions. While security products like Host Security Service (HSS), Cloud Firewall (CFW), and Web Application Firewall (WAF) can effectively safeguard cloud workloads, there are still other issues. For example, scattered alerts across security products make centralized management difficult and dispersed threat-handling processes slow response times. These issues hinder vulnerability detection, disrupt security operations, reduce threat response efficiency, and increase security risks. SecMaster provides security analysis, threat management, and security orchestration to effectively address the preceding issues. You can ingest log data of many cloud services, such as WAF, HSS, and CFW, into SecMaster in just a few clicks. You can also aggregate third-party log data from on-premises systems into SecMaster. Once the data is ingested, you can manage, search, and analyze all collected logs. With threat management and security orchestration, security teams can efficiently respond to cyber threats and enable automatic response to security incidents.

How Security Analysis Works

Figure 1 shows the workflow of security analysis.

Figure 1 Security analysis process
  1. Data collection: Logs are the objects of security analysis. You need to ingest cloud service logs or third-party security data into SecMaster. For details, see Enabling Log Access and Log Data Collection.
  2. Data preprocessing: Raw logs are cleaned and formatted to remove invalid information, ensuring the accuracy and efficiency of analysis.
  3. Threat detection: Potential security threats are identified based on the rules of log alert models. You can use the built-in model templates or customize alert models. For details, see Quickly Adding a Log Alert Model.
  4. Report generation: You can generate log audit reports to check the overall log audit status in the current workspace within a statistical period. For details about how to view log audit reports, see Checking Log Audit Overview.

Features and Operations Related to Security Analysis

Now that you understand the core concepts and application scenarios of security analysis, the following content describes its basic operations and advanced features. If you want to know more about these features and how to configure them in your services, check the detailed operation guide in Huawei Cloud documentation help center. Some helpful links are as follows:

  • Integrating cloud service logs in to SecMaster: Enabling Log Access.
  • Data collection: If third-party logs are required for security analysis, you need to integrate them into SecMaster. For details, see Log Data Collection.
  • Log query and analysis: After cloud service logs or third-party logs are integrated into SecMaster, you can query and analyze the collected log data in real time on the query and analysis page. For details, see Querying and Analyzing Logs.
  • Quickly adding a log alert model: You can configure custom threat detection rules for a log alert model. The log alert model will trigger an alert whenever the conditions defined in your custom rules are met. For details, see Quickly Adding a Log Alert Model.
  • Data delivery: You can deliver data to other pipelines or other cloud products in real time through security analysis so that you can store data or consume data with other systems. For details, see Data Delivery.
  • Log audit report: After security analysis is complete, you can generate log audit reports to review the overall log audit status in the current workspace over the specified statistical period. For details about how to view log audit reports, see Checking Log Audit Overview.
  • Security Orchestration: If you want to automatically respond to threats detected by security analysis, you can use security orchestration. Security orchestration combines security functions of different systems or components in a system involved in security operations in your organizations based on certain logical relationships to complete a specific security operations process and procedure. It aims to help security teams of enterprises and organizations quickly and efficiently respond to cyber threats and enable efficient and automated response to security incidents. For more details, see Security Orchestration.
  • Alert management: Alerts generated during security analysis are displayed on the Alerts page. You can handle alerts on that page. For more details, see Managing Alerts.