Home/Glossary/Security Information and Event Management (SIEM)

Security Information and Event Management (SIEM)

A platform that ingests security telemetry, correlates events, and surfaces alerts for investigation.

Security OperationsAlso called: "siem platform"

SIEM systems collect logs from endpoints, cloud services, firewalls, and applications to detect suspicious behavior.

What a SIEM does

  • Normalizes diverse log sources into a single schema.
  • Applies detection rules and machine learning to find anomalies.
  • Automates response actions through SOAR integrations.
  • Supports compliance reporting with long-term log retention.

Operational considerations

  • Tune detections to reduce false positives.
  • Establish runbooks for how analysts should triage alerts.
  • Ensure data sources cover modern SaaS and cloud services, not just on-prem systems.