Account compromise
Connect authentication, privilege changes, messaging activity, and data access.
A SIEM is a platform that centralizes, normalizes, and analyzes security logs from systems, applications, identities, and networks. It applies rules and correlations to detect suspicious activity, produce alerts, and support investigation. A SIEM does not monitor by itself: value depends on sources, detection use cases, and human response.
In one sentence
A SIEM brings security events together so teams can detect, investigate, and retain an actionable record.
Key points
Term at a glance
Sources send events such as sign-ins, privilege changes, API calls, firewall activity, endpoint alerts, and administrative actions. The SIEM converts them to a common format, enriches identities and assets, and makes the timeline searchable.
Detection combines rules, thresholds, correlations, and sometimes statistical models. A useful alert describes behaviour that needs verification and includes context. It is not automatic proof of an incident. An analyst validates identity, asset, sequence, and legitimate explanations before escalation.
Retention supports investigations and certain obligations, but must reflect volume, cost, and personal information. Critical logs require integrity, time synchronization, access control, and monitoring for collection failures. A source going silent is itself an event to handle.
Choose critical scenarios and affected assets before connecting sources.
Define events, fields, timestamps, identity, transport, access, retention, and collection health.
Link every rule to a threat, context, threshold, priority, and triage procedure.
Simulate behaviour, measure false positives and delay, close gaps, and document changes.
The SIEM observes a successful administrative sign-in from a new location, followed by a forwarding rule and unusual downloads. The correlation creates a high-priority alert. An analyst checks the user and device, revokes sessions under the playbook, and preserves the timeline. One isolated sign-in would not have been sufficient.
Connect authentication, privilege changes, messaging activity, and data access.
Detect authorization failures, administrative actions, and unusual API behaviour.
Reconstruct one timeline across identity, endpoint, network, cloud, and application.
Retain selected events with integrity, controlled access, and justified periods.
A SIEM is justified by the scenarios it helps detect and the investigation time it saves, not by ingested volume. Metrics include priority-use-case coverage, source health, triage time, false positives, and detected incidents. For a small business, a managed service or focused scope may be more realistic than a complex platform. The linked service page presents support; this page explains the choice.
EDR observes and responds on endpoints and servers. SIEM combines those alerts with identity, network, application, and cloud events. They complement each other: EDR is a rich source and SIEM connects sources.
No. Start from threats, investigations, and obligations, then collect the events and fields required. Logs with no use case consume budget and make search harder.
Some platforms use statistics or machine learning to identify anomalies and support triage. This does not replace dependable data, understandable rules, or human validation. Outputs need testing and monitoring.
Want to know which logs and detections are actually useful? We can frame risk, sources, and response.
Assess detection capabilities