Security Information and Event Management
Security information and event management, or SIEM, centralizes security logs and alerts from many systems. It gives a security team one place to search activity, correlate related events, detect suspicious behavior, and preserve evidence for investigation.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Security Information and Event Management
Security information and event management, or SIEM, is a centralized system for collecting, storing, searching, and analyzing security-relevant events. Its job is to turn records from many systems into evidence that a security operations team can use. A SIEM can expose a suspicious sequence that no individual device sees, such as a failed sign-in followed by a successful sign-in, a privilege change, and unusual access to sensitive data.
SIEM sits between telemetry-producing systems and people or tools that respond to security incidents. Endpoints, identity providers, network devices, cloud services, applications, and security products generate events. Collectors or agents transmit those events. Parsers interpret vendor-specific formats. Normalization maps equivalent fields into a common schema. Enrichment adds context such as asset criticality, identity, vulnerability, or threat intelligence. A storage and search layer retains the resulting records. Detection logic evaluates them and creates alerts or incidents for analysts.
event sources → collection → parsing → normalization → enrichment
↓
analyst ← incident ← alert ← detection and correlation ← searchable storage
This path is not instantaneous or lossless by default. A source may stop logging. A collector may queue or drop events. A parser may reject a changed format. Clocks may disagree. A retention rule may delete evidence before an investigation begins. Monitoring the pipeline is therefore part of operating a SIEM, not a separate housekeeping task.
Events, alerts, and incidents
An event is a record that something occurred. A successful sign-in is an event. An alert is a detection result that marks one event or a group of events for attention. An incident groups alerts and supporting evidence into a case that analysts can investigate and manage.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/92/final
Supports
- SIEM architecture, agent and agentless collection, parsing, normalization, filtering, aggregation, correlation, storage, analysis, and operational processes
- Limits, retention factors, log protection, quiz answers, reference rationale, and the 2006 timeline event
- https://csrc.nist.gov/pubs/sp/800/92/r1/ipd
Supports
- Log generation, transmission, storage, access, disposal, source planning, organizational improvement, and pipeline health
- Reference rationale and the 2023 timeline event
- https://csrc.nist.gov/pubs/sp/800/171/r3/final
Supports
- Event types and required audit-record content including what, when, where, source, outcome, and associated identities or objects
- Event definition and quiz grounding
- https://www.nist.gov/document/csf-20-implementations-pdf
Supports
- Continuous log monitoring, SIEM analysis, cross-source correlation, threat intelligence, impact assessment, alert delivery, tickets, and incident criteria
- Detection, correlation, triage, automation, quiz answers, and reference rationale
- https://csrc.nist.gov/pubs/sp/800/61/r3/final
Supports
- SIEM evidence inside incident detection, response, recovery, and cybersecurity risk management
- Incident-response limits, automation safeguards, quiz answer, and reference rationale
- https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/use-logging-on-business-systems
Supports
- Log enablement, centralization, monitoring, protection, retention, and assigned incident roles
- Reference-link rationale
- https://csrc.nist.gov/glossary/term/SIEM
Supports
- SIEM terminology and official-publication usage
- https://attack.mitre.org/datasources/
Supports
- Telemetry subjects used for detection coverage and source planning
- Data-source deprecation notice, quiz answer, and reference rationale
- https://www.rfc-editor.org/info/rfc3164/
Supports
- BSD syslog device, relay, and collector model, delivery and confidentiality limits, and August 2001 milestone
- https://www.rfc-editor.org/info/rfc5424/
Supports
- Standards-track syslog architecture, message format, timestamps, structured data, transport mappings, and security considerations
- Time and collection limits, quiz answer, reference rationale, and March 2009 milestone
- https://github.com/fabacab/awesome-cybersecurity-blueteam
Supports
- Discovery of Wazuh, Security Onion, Sigma, Logging Made Easy, Zeek, and Suricata for the SIEM and security-monitoring ecosystem
- https://github.com/sindresorhus/awesome
Supports
- Required starting point and discovery route to Awesome Cybersecurity Blue Team
- https://documentation.wazuh.com/current/getting-started/index.html
Supports
- Agent, server, decoder, rules, indexer, dashboard, log collection, threat hunting, and active response architecture
- Awesome-link rationale and Wazuh landscape placement
- https://docs.securityonion.net/en/2.4/
Supports
- Network and host visibility, alerts, search, cases, detections, and analyst workflows
- Awesome-link rationale
- https://sigmahq.io/docs/
Supports
- Portable log-detection rules, rule structure, processing, and conversion workflows
- Awesome-link rationale and timeline context
- https://github.com/SigmaHQ/sigma/commits/master/?after=f556d50a38791ab47353521c13d3d13a75f671c0+5599
Supports
- January 2017 initial repository history milestone
- https://github.com/cisagov/LME
Supports
- No-cost open-source centralized log collection, threat detection, and real-time alerting
- Awesome-link rationale
- https://docs.zeek.org/en/current/
Supports
- Structured network telemetry and log output used in SIEM collection and investigation
- Awesome-link rationale
- https://docs.suricata.io/en/latest/
Supports
- Network alerts, protocol records, flows, anomalies, and statistics usable as SIEM telemetry
- Awesome-link rationale
- https://www.splunk.com/en_us/products/enterprise-security.html
Supports
- Broad security-data search, detection, investigation, response, and federated-analysis placement
- https://learn.microsoft.com/en-us/azure/sentinel/overview
Supports
- Collection, connectors, normalization, analytics, incidents, hunting, automation, and playbooks
- Architecture claims, quiz answers, and Microsoft Sentinel landscape placement
- https://blogs.microsoft.com/blog/2019/02/28/announcing-new-cloud-based-technology-to-empower-cyber-defenders/
Supports
- February 2019 launch milestone and initial cloud-native SIEM placement
- https://cloud.google.com/security/products/security-operations
Supports
- Telemetry pipeline, YARA-L detections, search, threat intelligence, case management, SOAR, and pricing model
- Google Security Operations landscape placement
- https://cloud.google.com/blog/products/identity-security/an-update-on-chronicle-continuing-to-give-good-the-advantage
Supports
- November 2019 Chronicle Backstory and Google Cloud security milestone
- https://www.ibm.com/products/qradar-siem
Supports
- Centralized visibility, threat detection, compliance, and deployment placement
- https://www.elastic.co/security/siem
Supports
- Search, event analysis, detection, alerting, cases, endpoint context, and data-tier placement
- https://www.elastic.co/blog/introducing-elastic-siem/
Supports
- June 2019 Elastic SIEM launch, common schema, host and network workflows, and investigation interface
- https://www.sumologic.com/solutions/cloud-siem/
Supports
- Cloud SIEM normalization, rules, entity context, signals, and investigation placement
- https://www.rapid7.com/products/siem/
Supports
- Event ingestion, endpoint, user, network, and cloud context, detection, and investigation placement
- https://www.exabeam.com/product/new-scale-siem/
Supports
- User and entity timelines, behavior analytics, risk scoring, and case-context placement
- https://logrhythm.com/products/siem/
Supports
- Collection, analytics, alarms, case management, and response placement
- https://www.fortinet.com/products/siem/fortisiem
Supports
- Infrastructure discovery, event correlation, analytics, performance context, and incident placement
- https://www.opentext.com/products/enterprise-security-manager
Supports
- ArcSight event normalization, correlation, prioritization, rules, and investigation placement
- https://aws.amazon.com/blogs/security/aws-co-announces-release-of-the-open-cybersecurity-schema-framework-ocsf-project/
Supports
- August 2022 open security telemetry normalization milestone
