Security Information & Event Management
SIEM is a system that collects logs from different sources and analyzes them to detect security threats in real time.
Devices → Logs → SIEM → Analysis → Alerts 🚨
Log Collection → Gather data Normalization → Organize logs Correlation → Find patterns Alerting → Notify threats
Detect hacking attempts Monitor server activity Analyze user behavior Incident response
Splunk → Most popular SIEM IBM QRadar → Enterprise security ELK Stack → Open-source SIEM Microsoft Sentinel → Cloud SIEM
System logs Application logs Network logs Security logs
- Real-time monitoring - Threat detection - Faster incident response - Compliance reporting
SOC Analyst → Monitors SIEM Detect → Investigate → Respond