Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex SIEM
  • Getting started
  • KQL reference
  • Access management
  • Pricing policy

In this article:

  • Getting started
  • Create an investigation
  • Create a query
  • Analyze the results
  • What's next

Getting started with Yandex SIEM

Written by
Yandex Cloud
Updated at July 23, 2026
View in Markdown
  • Getting started
  • Create an investigation
  • Create a query
  • Analyze the results
  • What's next

Note

This feature is at the Preview stage. To get access, contact tech support or your account manager.

In this tutorial, you will create an investigation and run your first KQL (Kusto Query Language) query.

Getting startedGetting started

The Yandex SIEM section will appear in the Cloud Center interface as a Security Deck module after the access request is approved.

You need the ycem.editor role to use the service.

Create an investigationCreate an investigation

  1. Go to Security Deck.
  2. In the left-hand panel, select Yandex SIEM.
  3. Navigate to the Investigations tab.
  4. Click New investigation.
  5. Enter a name for your investigation, e.g., Failed login analysis.
  6. Under Description, add a description: Searching for failed console login attempts within the last 30 minutes.

Create a queryCreate a query

  1. In the query editor, enter the following KQL query:

    Events
    | project event_class, ['time']
    | limit 1
    

    This query:

    • Selects events from the Events table.
    • Displays the event_class and time fields.
    • Limits the result to a single entry.
  2. Set the time period to Last 30 minutes.

  3. Click the query run button.

Analyze the resultsAnalyze the results

After the query is completed, the results are displayed in a table with the following fields:

  • event_class: Event class.
  • time: Event time.

This is an example of a simple query which checks service performance. For more complex analysis, use additional queries and filters.

What's nextWhat's next

  • Learn more about investigations and queries.
  • Learn how to manage investigations.
  • Explore working with queries.
  • Review the KQL reference.

Was the article helpful?

Next
All guides
© 2026 Direct Cursus Technology L.L.C.