Security Information and Event Management
Security information and event management, or SIEM, centralizes security logs and alerts from many systems. It gives a security team one place to search activity, correlate related events, detect suspicious behavior, and preserve evidence for investigation.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Security Information and Event Management
A SIEM is the place where scattered security records stop being scattered, which is fortunate because asking twelve systems what happened at 09:04 is a poor use of anyone's afternoon. It collects events from endpoints, identity systems, network devices, cloud services, and applications, then keeps them searchable as evidence.
The useful mental picture is a pipeline. Events are collected, parsed, normalized, enriched, retained, and passed through detection logic. Each step needs the previous one to have behaved itself. A clever query cannot find an event that was never generated, and an investigation cannot retrieve evidence that retention has already removed. Computers are very consistent about this, even when the surrounding administration has been less so.
Keep the vocabulary tidy. An event says that something occurred. An alert says that a rule noticed activity worth attention. An incident is a managed case containing related evidence and response work. The alert is a lead, not a confession. Its job is to give an analyst a sensible place to begin asking what happened.
The surprising part is that more data is not automatically more visibility. Different sources name the same identity differently, clocks disagree, parsers change, and enrichment can grow stale. Normalization, meaning mapping equivalent fields to one common model, lets a detection join records that would otherwise pass each other in the night with great professionalism. Keep the raw event too, because a convenient field can still be wrong.
Detection starts with a threat hypothesis, not an impressive-looking pile of rules. Name the behavior, identify the events and fields that reveal it, test the logic against expected and benign activity, then measure the result. Tuning is a trade: a higher threshold cuts repeated alerts but can hide slow activity, while a broad exclusion can turn known behavior into a blind spot wearing a name badge.
Read the Introduction for the full path from collection to response. Use the Slides when the relationships need a quick visual map, and keep the Cheatsheet nearby when investigating field names, time, collection patterns, and failure signals. The Quiz checks whether the distinctions hold together. The Landscape is for comparing the kinds of products that implement this arrangement. The point is not to memorize a product label. Trace one question from source to evidence to action, and the rest of the machinery becomes much less mysterious.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/92/final
Supports
- SIEM architecture, agent and agentless collection, parsing, normalization, filtering, aggregation, correlation, storage, analysis, and operational processes
- Limits, retention factors, log protection, quiz answers, reference rationale, and the 2006 timeline event
- https://csrc.nist.gov/pubs/sp/800/92/r1/ipd
Supports
- Log generation, transmission, storage, access, disposal, source planning, organizational improvement, and pipeline health
- Reference rationale and the 2023 timeline event
- https://csrc.nist.gov/pubs/sp/800/171/r3/final
Supports
- Event types and required audit-record content including what, when, where, source, outcome, and associated identities or objects
- Event definition and quiz grounding
- https://www.nist.gov/document/csf-20-implementations-pdf
Supports
- Continuous log monitoring, SIEM analysis, cross-source correlation, threat intelligence, impact assessment, alert delivery, tickets, and incident criteria
- Detection, correlation, triage, automation, quiz answers, and reference rationale
- https://csrc.nist.gov/pubs/sp/800/61/r3/final
Supports
- SIEM evidence inside incident detection, response, recovery, and cybersecurity risk management
- Incident-response limits, automation safeguards, quiz answer, and reference rationale
- https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/use-logging-on-business-systems
Supports
- Log enablement, centralization, monitoring, protection, retention, and assigned incident roles
- Reference-link rationale
- https://csrc.nist.gov/glossary/term/SIEM
Supports
- SIEM terminology and official-publication usage
- https://attack.mitre.org/datasources/
Supports
- Telemetry subjects used for detection coverage and source planning
- Data-source deprecation notice, quiz answer, and reference rationale
- https://www.rfc-editor.org/info/rfc3164/
Supports
- BSD syslog device, relay, and collector model, delivery and confidentiality limits, and August 2001 milestone
- https://www.rfc-editor.org/info/rfc5424/
Supports
- Standards-track syslog architecture, message format, timestamps, structured data, transport mappings, and security considerations
- Time and collection limits, quiz answer, reference rationale, and March 2009 milestone
- https://github.com/fabacab/awesome-cybersecurity-blueteam
Supports
- Discovery of Wazuh, Security Onion, Sigma, Logging Made Easy, Zeek, and Suricata for the SIEM and security-monitoring ecosystem
- https://github.com/sindresorhus/awesome
Supports
- Required starting point and discovery route to Awesome Cybersecurity Blue Team
- https://documentation.wazuh.com/current/getting-started/index.html
Supports
- Agent, server, decoder, rules, indexer, dashboard, log collection, threat hunting, and active response architecture
- Awesome-link rationale and Wazuh landscape placement
- https://docs.securityonion.net/en/2.4/
Supports
- Network and host visibility, alerts, search, cases, detections, and analyst workflows
- Awesome-link rationale
- https://sigmahq.io/docs/
Supports
- Portable log-detection rules, rule structure, processing, and conversion workflows
- Awesome-link rationale and timeline context
- https://github.com/SigmaHQ/sigma/commits/master/?after=f556d50a38791ab47353521c13d3d13a75f671c0+5599
Supports
- January 2017 initial repository history milestone
- https://github.com/cisagov/LME
Supports
- No-cost open-source centralized log collection, threat detection, and real-time alerting
- Awesome-link rationale
- https://docs.zeek.org/en/current/
Supports
- Structured network telemetry and log output used in SIEM collection and investigation
- Awesome-link rationale
- https://docs.suricata.io/en/latest/
Supports
- Network alerts, protocol records, flows, anomalies, and statistics usable as SIEM telemetry
- Awesome-link rationale
- https://www.splunk.com/en_us/products/enterprise-security.html
Supports
- Broad security-data search, detection, investigation, response, and federated-analysis placement
- https://learn.microsoft.com/en-us/azure/sentinel/overview
Supports
- Collection, connectors, normalization, analytics, incidents, hunting, automation, and playbooks
- Architecture claims, quiz answers, and Microsoft Sentinel landscape placement
- https://blogs.microsoft.com/blog/2019/02/28/announcing-new-cloud-based-technology-to-empower-cyber-defenders/
Supports
- February 2019 launch milestone and initial cloud-native SIEM placement
- https://cloud.google.com/security/products/security-operations
Supports
- Telemetry pipeline, YARA-L detections, search, threat intelligence, case management, SOAR, and pricing model
- Google Security Operations landscape placement
- https://cloud.google.com/blog/products/identity-security/an-update-on-chronicle-continuing-to-give-good-the-advantage
Supports
- November 2019 Chronicle Backstory and Google Cloud security milestone
- https://www.ibm.com/products/qradar-siem
Supports
- Centralized visibility, threat detection, compliance, and deployment placement
- https://www.elastic.co/security/siem
Supports
- Search, event analysis, detection, alerting, cases, endpoint context, and data-tier placement
- https://www.elastic.co/blog/introducing-elastic-siem/
Supports
- June 2019 Elastic SIEM launch, common schema, host and network workflows, and investigation interface
- https://www.sumologic.com/solutions/cloud-siem/
Supports
- Cloud SIEM normalization, rules, entity context, signals, and investigation placement
- https://www.rapid7.com/products/siem/
Supports
- Event ingestion, endpoint, user, network, and cloud context, detection, and investigation placement
- https://www.exabeam.com/product/new-scale-siem/
Supports
- User and entity timelines, behavior analytics, risk scoring, and case-context placement
- https://logrhythm.com/products/siem/
Supports
- Collection, analytics, alarms, case management, and response placement
- https://www.fortinet.com/products/siem/fortisiem
Supports
- Infrastructure discovery, event correlation, analytics, performance context, and incident placement
- https://www.opentext.com/products/enterprise-security-manager
Supports
- ArcSight event normalization, correlation, prioritization, rules, and investigation placement
- https://aws.amazon.com/blogs/security/aws-co-announces-release-of-the-open-cybersecurity-schema-framework-ocsf-project/
Supports
- August 2022 open security telemetry normalization milestone
- https://www.elastic.co/blog/false-positives-automated-siem-investigations-elastic-tines
Supports
- Field Notes on trusted context, automated triage, exception inventory, and closure conditions
