Enhancing Security Operations Center Efficiency throughMulti-Model Integration of Large Language Models and SIEMSystems | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Enhancing Security Operations Center Efficiency throughMulti-Model Integration of Large Language Models and SIEMSystems Yuvraj Singh, ND Patel, Shishir Kumar Shandilya This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5615639/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract The rising rates of cyberattacks necessitate advanced solutions within Security Operations Centers (SOCs). This research explores the integration of Large Language Models (LLMs) with Security Information and Event Management (SIEM) systems to enhance the triage processes of Tier 1 SOC analysts. We evaluate five LLMs—GPT-4, GPT-3.5, LLaMA 3, Mixtral 8x22B, and OpenHermes 2.5 Mistral 7B—on their ability to classify alerts as 'interesting' or 'not interesting'. Our proposed framework, consisting of an alert generation module, an LLM agent, and a reporting module, was tested using Wazuh SIEM integrated with CALDERA for adversary emulation. The results demonstrate that GPT-4 achieved the highest accuracy with a precision of 94%, recall of 92%, and an F1-score of 93%, significantly outperforming the other models. The integration of LLMs accelerated preliminary triage by reducing the average processing time per alert by 40% and decreased the cognitive load on analysts by automating up to 60% repetitive tasks. However, challenges such as hallucinations—occurring in approximately 5% of cases—integration complexities and privacy risks associated with handling sensitive data were observed. To address these issues, we propose a hybrid approach where LLMs act as co-pilots alongside analysts, incorporating strategies for model transparency, bias detection, and compliance with data privacy regulations. These findings offer practical insights for enhancing SOC efficiency and resilience against evolving cyber threats, emphasizing the importance of prompt optimization, continuous learning, and industry collaboration for large-scale alert training in future studies. Large Language Models Security Operations Centers SIEM systems GPT-4 Cognitive load reduction Model transparency Privacy risks Prompt optimization Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5615639","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":391907563,"identity":"42bab37e-99de-4c02-bad9-9b16bca9bbd0","order_by":0,"name":"Yuvraj Singh","email":"","orcid":"","institution":"Vellore Institute of Technology University","correspondingAuthor":false,"prefix":"","firstName":"Yuvraj","middleName":"","lastName":"Singh","suffix":""},{"id":391907564,"identity":"5f33f681-0478-4f10-983c-adec13a988f4","order_by":1,"name":"ND Patel","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA00lEQVRIiWNgGAWjYFCCBBBhIcfAwANGDAzMxGg5wCBhTLqWxAa4FkLAnD334OcPFRLpG473HpN4w2Anz8DOewCvFsued8kSB85I5G44cy5Ncg5DsmEDM18CXi0GN3IMJA62AbXcyDGT5mFgTmBg5jEgpMX4x8F/EukGEC31RGkxkzjYIJEA1XKYCC1n3qVZnDkmYTjzzBljyzkGxw3bCGo5nnv4RkWNjTzf8R7DG28qquX5+c/g14IcFywSDEDFbATUo2hh/kBY9SgYBaNgFIxEAAAKQECiF5g1GAAAAABJRU5ErkJggg==","orcid":"","institution":"Vellore Institute of Technology University","correspondingAuthor":true,"prefix":"","firstName":"ND","middleName":"","lastName":"Patel","suffix":""},{"id":391907565,"identity":"02749c82-dfde-4afc-94ce-ab0d3d5b5369","order_by":2,"name":"Shishir Kumar Shandilya","email":"","orcid":"","institution":"Devi Ahilya Vishwavidyalaya","correspondingAuthor":false,"prefix":"","firstName":"Shishir","middleName":"Kumar","lastName":"Shandilya","suffix":""}],"badges":[],"createdAt":"2024-12-10 10:23:42","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-5615639/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5615639/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":98438101,"identity":"d8755160-e002-46d7-8d31-d5505c16cd3c","added_by":"auto","created_at":"2025-12-17 16:58:39","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1969934,"visible":true,"origin":"","legend":"","description":"","filename":"MultiModelIntegrationofLLMsandSIEM.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5615639/v1_covered_5f9be19f-5639-450b-bb92-cadc84c6dcab.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Enhancing Security Operations Center Efficiency throughMulti-Model Integration of Large Language Models and SIEMSystems","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Large Language Models, Security Operations Centers, SIEM systems, GPT-4, Cognitive load reduction, Model transparency, Privacy risks, Prompt optimization","lastPublishedDoi":"10.21203/rs.3.rs-5615639/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5615639/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"The rising rates of cyberattacks necessitate advanced solutions within Security Operations Centers (SOCs). This research explores the integration of Large Language Models (LLMs) with Security Information and Event Management (SIEM) systems to enhance the triage processes of Tier 1 SOC analysts. We evaluate five LLMs—GPT-4, GPT-3.5, LLaMA 3, Mixtral 8x22B, and OpenHermes 2.5 Mistral 7B—on their ability to classify alerts as 'interesting' or 'not interesting'. Our proposed framework, consisting of an alert generation module, an LLM agent, and a reporting module, was tested using Wazuh SIEM integrated with CALDERA for adversary emulation. The results demonstrate that GPT-4 achieved the highest accuracy with a precision of 94\\%, recall of 92\\%, and an F1-score of 93\\%, significantly outperforming the other models. The integration of LLMs accelerated preliminary triage by reducing the average processing time per alert by 40\\% and decreased the cognitive load on analysts by automating up to 60\\% repetitive tasks. However, challenges such as hallucinations—occurring in approximately 5\\% of cases—integration complexities and privacy risks associated with handling sensitive data were observed. To address these issues, we propose a hybrid approach where LLMs act as co-pilots alongside analysts, incorporating strategies for model transparency, bias detection, and compliance with data privacy regulations. These findings offer practical insights for enhancing SOC efficiency and resilience against evolving cyber threats, emphasizing the importance of prompt optimization, continuous learning, and industry collaboration for large-scale alert training in future studies.","manuscriptTitle":"Enhancing Security Operations Center Efficiency throughMulti-Model Integration of Large Language Models and SIEMSystems","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-12-20 06:51:35","doi":"10.21203/rs.3.rs-5615639/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"04a02961-5668-4254-b26a-5a9e1909c334","owner":[],"postedDate":"December 20th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-12-16T21:53:35+00:00","versionOfRecord":[],"versionCreatedAt":"2024-12-20 06:51:35","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5615639","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5615639","identity":"rs-5615639","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.