Security Information and Event Management (SIEM)
A platform that collects, normalises and correlates log and event data from across an organisation's IT environment to detect threats, support investigations and meet log retention and reporting requirements.
A SIEM ingests logs from sources such as firewalls, servers, endpoints, identity providers, cloud services and applications, parses them into a common schema and stores them for search. Correlation rules and analytics, including user and entity behaviour analytics, combine events to detect patterns such as repeated failed logins followed by a success, or access from unusual locations, and raise alerts for analysts.
The SIEM is usually the central console of a security operations centre. Beyond detection, it supports incident investigation, threat hunting and compliance, since many frameworks and regulations expect security logs to be collected, protected and retained; PCI DSS, for example, has detailed requirements for logging and monitoring access to cardholder data. SIEMs increasingly integrate with SOAR platforms to automate response steps.
Value depends on log source coverage, data quality and well-tuned detection content, as poorly tuned rules produce alert fatigue. Licensing is often based on data volume, so organisations decide carefully which logs to ingest and how long to keep them. Detection coverage is commonly mapped against MITRE ATT&CK, and machine learning-based anomaly detection complements rather than replaces rule-based correlation.
Key points
- Centralises and correlates logs from across the environment.
- Usually the core tool of a security operations centre.
- Supports compliance requirements for log collection and retention.
- Effectiveness depends on log coverage and well-tuned detection rules.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Security Operations Centre (SOC)Cybersecurity & Compliance
- Security Orchestration, Automation and Response (SOAR)Cybersecurity & Compliance
- Extended Detection and Response (XDR)Cybersecurity & Compliance
- Anomaly DetectionAI & Machine Learning
- Incident ResponseCybersecurity & Compliance
- MITRE ATT&CKCybersecurity & Compliance