SIEM
Also known as: Security Information and Event Management
Following adds this technology to your private workspace so related learning is easier to organise and revisit.
What is SIEM?
Security information and event management centralises security telemetry for detection, investigation, reporting and response. This profile connects the concept to KBY's practical engineering guidance.
A SIEM ingests and normalises events, correlates them through analytics and preserves searchable evidence. Coverage, parsing quality, identity and asset context, retention, detection tuning and response ownership determine whether it produces useful signals instead of alert volume.
Detect and investigate security activity across multiple systems from centralised evidence.
- Centralized security logging
- Threat detection and correlation
- Compliance auditing
1 resource for SIEM
Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.
Learn and operate with SIEM
Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.
Lexicon Definitions(1)
Start here: understand the core vocabulary.