What is Security information and event management (SIEM)?
A platform that collects and stores logs from across your environment, normalises them and runs detection rules, so security teams can search, alert and report from one place.
How it works
A SIEM ingests logs from firewalls, servers, identity systems, cloud platforms and applications. Analysts write correlation rules to spot suspicious patterns, and the stored logs support investigations and compliance evidence.
Modern cloud SIEMs such as Microsoft Sentinel have reduced the infrastructure burden, but a SIEM still needs ongoing rule tuning and people watching it.
Key points
- Central log collection and retention
- Correlation rules and analytics for detection
- Search for investigations and threat hunting
- Evidence for audits and regulators
Common questions
Does MDR replace a SIEM?
Not necessarily. Many MDR services, including Pulse, connect to an existing SIEM and use it as a data source.
How long should a SIEM keep logs?
It depends on your regulatory and investigation needs. Twelve months is a common baseline; some regulations require longer.
Talk to someone who does this every day
Questions about SIEM? Our team will give you a straight answer.