SIEM
Also known as: Security Information and Event Management
SIEM (Security Information and Event Management) centrally collects log data from many systems and analyzes it for suspicious patterns.
SIEM (Security Information and Event Management) pulls log data from many systems – firewalls, servers, login services, endpoints – into one central place and analyzes it together. The point is to catch patterns that wouldn't stand out in any single system's logs on its own, such as a login from abroad shortly after a failed login attempt in the office.
In practice, every connected system continuously feeds log entries into the SIEM, which derives rules or statistical anomalies from them and raises an alert on a match. For this to actually work, someone has to maintain the rules and review the alerts; a SIEM without that ongoing work just produces a growing pile of unread notifications.
A SIEM is simply overkill for many small and mid-sized businesses: the effort to set it up and monitor it around the clock often outweighs the benefit when only a handful of systems are in use. It starts to make sense once several systems with security-relevant logs need to be brought together, or the SIEM is part of an existing SOC service.
What it means in practice
For most SMBs, a dedicated SIEM only pays off once enough different systems are in use that nobody could reasonably review their logs one by one anymore. A sign that it's missing where it's actually needed is an incident where the relevant logs existed but nobody pulled them together in time. NDVDL gives an honest assessment of whether a SIEM is worth the effort, or whether simpler centralized logging is enough.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.