Your question is SIEM Anomaly Detection Approach. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
Can you discuss your experience with SIEM tools and identifying anomalous behavior?