International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1714786

1714786 Vol 9 · Issue 9 Download Paper

Automated SIEM Alert Classification using Random Forest for Cybersecurity

Sanjay Raj R Palanikumar R Manikandan

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Security

DOI: 10.64388/IREV9I9-1714786

Abstract

The primary objective of this project is to design and implement an automated SIEM alert classification system that leverages machine learning to enhance cybersecurity monitoring and response. Modern organizations rely on SIEM (Security Information and Event Management) tools to collect, aggregate, and analyze security event logs from multiple sources such as firewalls, intrusion detection systems (IDS), servers, and applications. However, these systems often generate a massive volume of alerts on a daily basis. To address this challenge, the proposed project employs the Random Forest algorithm to intelligently classify alerts into categories. The objective is not only to build a classifier but also to establish a structured pipeline that includes data preprocessing, feature engineering, model training, classification, and visualization. Through this approach, the project aims to reduce the noise generated by false alerts, prioritize critical incidents, and thereby optimize the decision-making process of security teams. Additionally, the system is designed to be scalable and adaptable, capable of processing large volumes of data efficiently while maintaining high accuracy. By integrating visualization and reporting mechanisms, the system also enhances interpretability, allowing analysts to understand feature importance and classification trends. Ultimately, the objective is to demonstrate how machine learning, particularly Random Forest, can be effectively applied in the cybersecurity domain to automate repetitive tasks, reduce manual workload, and significantly improve the accuracy, reliability, and efficiency of SIEM alert management.

References

[1] Ali, G. (2025). Enhancing cybersecurity incident response: AI-driven automation of SIEM alert classification using Random Forest. Journal of Cybersecurity Research, 12(3), 215-229. DOI: 10.1016/j.jocyr.2025.03.004

[2] Turcotte, M., Labreche, F., & Paquette, S.-O. (2025). Automated Alert Classification and Triage (AACT): An intelligent system for the prioritisation of cybersecurity alerts. arXiv Preprints. DOI: 10.48550/arXiv.2505.09843

[3] Chamkar, S. A. (2025). ML-Driven Log Analysis for Real-Time Cyber Threat Detection: A Comparative Study of Machine Learning Models. Preprints. DOI: 10.20944/preprints202504.2197.v1

[4] Ban, T. (2023). AI-Assisted SIEM Framework for Effective Incident Response. Applied Sciences, 13(11), 6610. DOI: 10.3390/app13116610

[5] Gelman, B. (2023). Machine Learning-Based Security Alert Screening with Focal Loss. ResearchGate. DOI: 10.2139/ssrn.3737895

[6] Roelofs, T. M. (2024). Blending Security Alerts for Attack Detection. Zhauniarovich. Available at: https://zhauniarovich.com/publication/2024/roelofs2024finding/roelofs2024finding.pdf

[7] Bryant, B. D. (2020). Improving SIEM alert metadata aggregation with a novel kill-chain based classification model. ScienceDirect. DOI: 10.1016/j.comnet.2020.103024

[8] Chamkar, S. A. (2025). Improving Threat Detection in Wazuh Using Machine Learning. MDPI. DOI: 10.3390/26248034

[9] Mohamed, N. (2025). Artificial intelligence and machine learning in cybersecurity. SpringerLink. DOI: 10.1007/s10115-025-02429-y

How to cite this paper

Sanjay Raj R, Palanikumar R, Manikandan "Automated SIEM Alert Classification using Random Forest for Cybersecurity" Iconic Research And Engineering Journals Volume 9 Issue 9 2026 Page 84-89 https://doi.org/10.64388/IREV9I9-1714786
Sanjay Raj R, Palanikumar R, Manikandan "Automated SIEM Alert Classification using Random Forest for Cybersecurity" Iconic Research And Engineering Journals, vol. 9, no. 9, Mar. 2026, doi: https://doi.org/10.64388/IREV9I9-1714786
Sanjay Raj R, Palanikumar R, Manikandan (2026). Automated SIEM Alert Classification using Random Forest for Cybersecurity. Iconic Research And Engineering Journals, 9(9). doi: https://doi.org/10.64388/IREV9I9-1714786
Sanjay Raj R, Palanikumar R, Manikandan "Automated SIEM Alert Classification using Random Forest for Cybersecurity" Iconic Research And Engineering Journals, vol. 9, no. 9, Mar. 2026. Crossref, https://doi.org/10.64388/IREV9I9-1714786
@article{1714786,
      author = {Sanjay Raj R, Palanikumar R, Manikandan},
      title = {Automated SIEM Alert Classification using Random Forest for Cybersecurity},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {9},
      pages = {84-89},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1714786.pdf},
      abstract = {The primary objective of this project is to design and implement an automated SIEM alert classification system that leverages machine learning to enhance cybersecurity monitoring and response. Modern organizations rely on SIEM (Security Information and Event Management) tools to collect, aggregate, and analyze security event logs from multiple sources such as firewalls, intrusion detection systems (IDS), servers, and applications. However, these systems often generate a massive volume of alerts on a daily basis. To address this challenge, the proposed project employs the Random Forest algorithm to intelligently classify alerts into categories. The objective is not only to build a classifier but also to establish a structured pipeline that includes data preprocessing, feature engineering, model training, classification, and visualization. Through this approach, the project aims to reduce the noise generated by false alerts, prioritize critical incidents, and thereby optimize the decision-making process of security teams. Additionally, the system is designed to be scalable and adaptable, capable of processing large volumes of data efficiently while maintaining high accuracy. By integrating visualization and reporting mechanisms, the system also enhances interpretability, allowing analysts to understand feature importance and classification trends. Ultimately, the objective is to demonstrate how machine learning, particularly Random Forest, can be effectively applied in the cybersecurity domain to automate repetitive tasks, reduce manual workload, and significantly improve the accuracy, reliability, and efficiency of SIEM alert management.},
      month = {March},
      doi = {https://doi.org/10.64388/IREV9I9-1714786}
  }