Defense
SIEM (Security Information and Event Management)
System for collecting, analyzing and correlating security events
SIEM (Security Information and Event Management) is a comprehensive platform for centralized collection, storage, analysis, and correlation of security events from across an organization's IT infrastructure.
Key Functions
- Log Collection — collecting logs from all sources
- Normalization — data normalization
- Correlation — event linking
- Alerting — incident notifications
- Reporting — compliance reporting
Data Sources
- Servers and workstations
- Network equipment
- Security systems (IDS, WAF, AV)
- Cloud services
- Applications
Popular SIEM Solutions
- Splunk
- IBM QRadar
- Microsoft Sentinel
- Elastic Security
- Wazuh (open source)
Use Cases
- Intrusion detection
- Incident investigation
- Compliance (PCI DSS, SOX, HIPAA)
Related Terms
Category
WAF, SIEM, SOC, EDR, protection and monitoring tools