SIEM (Security Information and Event Management)

SIEM (Security Information and Event Management) is the term for systems that centrally collect, correlate and evaluate security-relevant log and event data from the entire IT environment. The aim is to make attacks and anomalies visible across system boundaries.

To this end, a SIEM brings together log data from servers, network components, applications, identity services and security tools, normalizes it and applies correlation rules: individual events that appear harmless on their own form an attack pattern in context and trigger alerts. In addition, the SIEM serves as an auditable archive for compliance evidence. Classic implementations, however, reach their limits: laborious rule maintenance, high alert volumes and costs that grow with the data volume.

A SIEM is typically operated in the Security Operations Center (SOC), whose analysts work with the alerts generated. The cloud-based, analytics-driven further development of the concept is described by the term Next-Gen SIEM.