How a SIEM works
A SIEM ingests logs from servers, laptops, firewalls, cloud services and business applications, normalises them into a common format and applies correlation rules. For example, a login from an unusual country followed by a mass download can trigger an alert that neither event would raise on its own.
SIEM, SOAR and XDR
A SIEM detects and alerts. A SOAR automates response steps, such as disabling an account or opening a ticket. XDR focuses on correlating data from a vendor's own security products, while a SIEM is designed to take data from many sources.
What makes a SIEM useful
A SIEM is only as good as the logs it receives and the rules it runs. Without a team to tune detections and review alerts, it tends to generate noise. That is why it is usually operated together with a SOC.
Where it shows up in compliance
Log collection, retention and monitoring are required by ISO 27001 (Annex A 8.15 and 8.16), the ENS and NIS2, and a SIEM is the usual way to meet them.




