Skip to main content
StandardCurrent

SIEM

Also known as: Security Information and Event Management

Following adds this technology to your private workspace so related learning is easier to organise and revisit.

Technology explained

What is SIEM?

Security information and event management centralises security telemetry for detection, investigation, reporting and response. This profile connects the concept to KBY's practical engineering guidance.

A SIEM ingests and normalises events, correlates them through analytics and preserves searchable evidence. Coverage, parsing quality, identity and asset context, retention, detection tuning and response ownership determine whether it produces useful signals instead of alert volume.

Primary purpose

Detect and investigate security activity across multiple systems from centralised evidence.

Typical environments
Enterprise Security Operations Centers (SOC)
Typical use cases
  • Centralized security logging
  • Threat detection and correlation
  • Compliance auditing
Connected knowledge

1 resource for SIEM

Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.

Technology journey

Learn and operate with SIEM

Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.

Lexicon Definitions(1)

Start here: understand the core vocabulary.