GlossarySOC and monitoring

SIEM

Short answer

A SIEM (Security Information and Event Management) is a platform that collects logs and events from across an organisation's systems, correlates them and raises alerts when it detects activity that may indicate an attack. It is the main tool a SOC uses to monitor an environment.

How a SIEM works

A SIEM ingests logs from servers, laptops, firewalls, cloud services and business applications, normalises them into a common format and applies correlation rules. For example, a login from an unusual country followed by a mass download can trigger an alert that neither event would raise on its own.

SIEM, SOAR and XDR

A SIEM detects and alerts. A SOAR automates response steps, such as disabling an account or opening a ticket. XDR focuses on correlating data from a vendor's own security products, while a SIEM is designed to take data from many sources.

What makes a SIEM useful

A SIEM is only as good as the logs it receives and the rules it runs. Without a team to tune detections and review alerts, it tends to generate noise. That is why it is usually operated together with a SOC.

Where it shows up in compliance

Log collection, retention and monitoring are required by ISO 27001 (Annex A 8.15 and 8.16), the ENS and NIS2, and a SIEM is the usual way to meet them.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub