Penerapan IBM Qradar Security Information and Event Management (SIEM) Untuk Deteksi Ancaman Keamanan Jaringan Pada Infrastruktur Job Tomori
Downloads
Penelitian ini membahas penerapan IBM QRadar Security Information and Event Management (SIEM) dalam mendukung proses monitoring dan deteksi ancaman pada jaringan. Seiring dengan berkembangnya infrastruktur jaringan, jumlah log dan aktivitas yang tercatat juga semakin besar, sehingga sulit dianalisis secara manual menggunakan metode konvensional. Oleh karena itu, dibutuhkan sistem yang mampu mengelola dan menganalisis data secara terpusat. Metode yang digunakan dalam penelitian ini meliputi instalasi dan konfigurasi QRadar pada lingkungan jaringan uji, integrasi berbagai sumber log seperti server, firewall, dan endpoint, serta pembuatan aturan korelasi untuk mengidentifikasi pola aktivitas yang mencurigakan. Proses pengamatan dilakukan untuk melihat kemampuan sistem dalam mendeteksi beberapa jenis ancaman, seperti percobaan login berulang, akses tidak sah, dan aktivitas lalu lintas yang tidak normal. Hasil penelitian menunjukkan bahwa QRadar mampu mengolah data log dalam jumlah besar dan menyajikan informasi dalam bentuk notifikasi serta tampilan dashboard secara real-time. Hal ini membantu administrator dalam mengenali potensi ancaman lebih cepat dan mengambil tindakan yang diperlukan. Secara keseluruhan, penggunaan SIEM berbasis QRadar dapat meningkatkan efektivitas pemantauan keamanan jaringan.
Alanazi, M., Mahmood, A., & Chowdhury, M. J. M. (2023). SCADA vulnerabilities and attacks: A review of the state-of-the-art and open issues. Computers & Security, 125, 103028. https://doi.org/10.1016/j.cose.2022.103028
Anggraeni, R., & Maulani, I. E. (2023). Pengaruh teknologi informasi terhadap perkembangan bisnis modern. Jurnal Sosial Teknologi, 3(2), 94–98.
Aulia, B. W., Rizki, M., Prindiyana, P., & Surgana, S. (2023). Peran krusial jaringan komputer dan basis data dalam era digital. JUSTINFO | Jurnal Sistem Informasi dan Teknologi Informasi, 1(1), 9–20.
Bezas, K., & Filippidou, F. (2024). Revolutionizing SIEM security: An innovative correlation engine design for multi-layered attack detection. Sensors, 24(15), 4901. https://doi.org/10.3390/s24154901
Carrera, B., La Torre, D., & Tavana, M. (2024). A comprehensive investigation of clustering algorithms for user and entity behavior analytics. Frontiers in Big Data, 7, 1375818. https://doi.org/10.3389/fdata.2024.1375818
Chic, S. A., & Bilqisthi, M. F. (2024). Tantangan dan peluang blockchain di era digital dalam bidang keamanan data dan transaksi digital. Journal of Comprehensive Science (JCS), 3(11).
Fausto, A., Gaggero, G. B., Patrone, F., Girdinio, P., & Marchese, M. (2021). Toward the integration of cyber and physical security monitoring systems for critical infrastructures. Sensors, 21(21), 6970. https://doi.org/10.3390/s21216970
González-Granadillo, G., González-Zarzosa, S., & Diaz, R. (2021). Security information and event management (SIEM): Analysis, trends, and usage in critical infrastructures. Sensors, 21(14), 4759. https://doi.org/10.3390/s21144759
Hoshmand, M. O., & Ratnawati, S. (2023). Analisis keamanan infrastruktur teknologi informasi dalam menghadapi ancaman cybersecurity. Jurnal Sains dan Teknologi, 5(2), 679–686.
Mohammed, A. S., Reinecke, P., Burnap, P., Rana, O., & Anthi, E. (2022). Cybersecurity challenges in the offshore oil and gas industry: An industrial cyber-physical systems (ICPS) perspective. ACM Transactions on Cyber-Physical Systems, 6(3), 1–27. https://doi.org/10.1145/3548691
Muhammad, A. R., Sukarno, P., & Wardana, A. A. (2023). Integrated security information and event management (SIEM) with intrusion detection system (IDS) for live analysis based on machine learning. Procedia Computer Science, 217, 1406–1415. https://doi.org/10.1016/j.procs.2022.12.339
Nabila, A. Z., Yasmine, S., & Stevano, A. (2025). Peran cloud computing terhadap efisiensi infrastruktur dan transformasi jaringan organisasi: Studi literatur. Jurnal Sains dan Teknologi 4.0, 3(1), 19–23.
Nandaputra, J., Sukarno, P., & Wardana, A. A. (2024). Detection and prevention system on computer network to handle distributed denial-of-service (DDoS) attack in realtime and multi-agent. Proceedings of the 2024 10th International Conference on Computer Technology Applications (ICCTA), 237–241. https://doi.org/10.1145/3674558.3674592
Prasetia, O., Machfud, S., & Ibnurhus, G. A. (2024). Sosialiasi pengenalan pentingnya cyber security guna menjaga keamanan data di era digital pada siswa/i SMK Bakti Idhata Jakarta. JIPM: Jurnal Inovasi Pengabdian Masyarakat, 2(1), 16–20.
Safarzadeh, M., Bagheri, M., Zamani, B., & Shafiei, H. (2024). Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs. PLOS ONE, 19(3), e0299368. https://doi.org/10.1371/journal.pone.0299368
Sani, A., Shabrina, F., Dana, W. P., Hardini, I. R., Juansa, A., Zulfikar, Z., Kumara, I. M. S., Budiasto, J., Rianty, E., & Angin, J. T. K. P. (2025). Pengantar teknologi informasi: Dampak dan peluang perkembangan teknologi informasi dalam dunia kerja dan bisnis. Star Digital Publishing.
Stergiopoulos, G., Gritzalis, D. A., & Limnaios, E. (2020). Cyber-attacks on the oil & gas sector: A survey on incident assessment and attack patterns. IEEE Access, 8, 128440–128475. https://doi.org/10.1109/ACCESS.2020.3008937
Tommy, S., & Nasution, M. I. P. (2025). Evaluasi manajemen risiko keamanan siber pada infrastruktur digital pemerintah: Studi kasus Pusat Data Nasional (PDN). Jurnal Manajemen Ekonomi dan Bisnis, 4(1), 1–26.
Winkler, A. M., Bhattacharya, A., & Bhattacharya, P. (2025). Proactive threat detection in enterprise systems using Wazuh: A MITRE ATT&CK evaluation. Computers & Security, 154, 104460. https://doi.org/10.1016/j.cose.2025.104460
Yadav, G., & Paul, K. (2021). Architecture and security of SCADA systems: A review. International Journal of Critical Infrastructure Protection, 34, 100433. https://doi.org/10.1016/j.ijcip.2021.100433
Yonatan, Y. K., Saepudin, T. H., Siaga, A. P., Arifin, M., Firmansyah, R. N., Daffa, F. M., & Alamsyah, R. (2024). Dampak teknologi lanjutan terhadap keamanan data manajemen sekuriti: Tantangan dan peluang di era digital. Journal of Engineering Environmental Energy and Science, 3(2), 59–66.
Copyright (c) 2026 Muhammad Aydin Rafif Reyfan, Oky Tria Saputra

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.





