TopicCybersecurity →
Simple definition
A platform that centralizes and analyzes security logs of many systems.
Technical definition
Security Information and Event Management collects events, normalizes them, correlates them and triggers alerts according to rules or models.
What is it used for ?
Identify suspicious behaviour and facilitate investigations.
Practical example
One SIEM can correlate several failures VPN then a successful connection from an unusual address.
Common issues
- Too many false positives
- Missing sources of the log
- Insufficient detention
Related terms
SOC · IOC · Event observer
Key takeaway: This entry explains the general operation of the term. Exact settings may vary depending on software, vendors and environments.