SIEM
Security
Security Information and Event Management platform aggregating logs, correlating events, and generating alerts.
Definition
A SIEM ingests logs, normalizes data, correlates events, and produces alerts and dashboards. It supports investigations and compliance reporting when configured correctly.
Why this matters
Why it matters: Good logging and correlation reduce detection time and limit exposure of sensitive data.
Example
Example: Send auth logs, firewall logs, and endpoint alerts into a SIEM with detection rules and incident workflows.