Defense

SIEM (Security Information and Event Management)

System for collecting, analyzing and correlating security events

SIEM (Security Information and Event Management) is a comprehensive platform for centralized collection, storage, analysis, and correlation of security events from across an organization's IT infrastructure.

Key Functions

  • Log Collection — collecting logs from all sources
  • Normalization — data normalization
  • Correlation — event linking
  • Alerting — incident notifications
  • Reporting — compliance reporting

Data Sources

  • Servers and workstations
  • Network equipment
  • Security systems (IDS, WAF, AV)
  • Cloud services
  • Applications

Popular SIEM Solutions

  • Splunk
  • IBM QRadar
  • Microsoft Sentinel
  • Elastic Security
  • Wazuh (open source)

Use Cases

  • Intrusion detection
  • Incident investigation
  • Compliance (PCI DSS, SOX, HIPAA)

Category

WAF, SIEM, SOC, EDR, protection and monitoring tools