166 terms · 75/46/45
Defense № 015 · class: monitoring / response

SIEM

SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.

Term

description · examples · notes

SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.

Description

SIEM enables searching, analysis, and visualization of security data, alert generation based on defined rules, and compliance monitoring against regulatory requirements. It serves as the central visibility point for security operations.

SIEM effectiveness depends on the quality of data sources, precision of correlation rules, and the team's ability to process and investigate generated alerts.

What people often say

  • SIEM automatically discovers all threats immediately after installation.
  • More logs mean better detection (without quality rules, more logs mean more noise).

Covers / does not cover

Covers

  • Centralized log collection from servers, network devices, applications, and security tools
  • Cross-source event correlation for detecting complex attacks
  • Alert generation based on rules and anomalies
  • Regulatory compliance reporting

Does not cover

  • Automated incident response (that requires additional automation or SOAR)
  • Endpoint detection without appropriate data sources
  • Attack prevention (SIEM detects, it does not block)

Mentioned in the news

Composite

Threats

reduces 6

Techniques

neutralizes 14