SIEM
Definition
Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies correlation rules to generate alerts. Examples include Splunk, IBM QRadar, Microsoft Sentinel, and the open-source Wazuh. The primary infrastructure for large-scale log correlation.
- Full name
- Security Information and Event Management
- Function
- Ingest, normalise, and correlate log streams
- Examples
- Splunk, IBM QRadar, Microsoft Sentinel, Wazuh
- Output
- Correlated alerts across data sources
- Sub-field
- Digital forensics and incident response
Common questions
Why is a SIEM described as the primary infrastructure for large-scale log correlation rather than just log storage?+
Beyond storing logs, a SIEM normalises data from disparate sources into a common schema and applies correlation rules across them, which lets an analyst spot a multi-stage attack pattern that no single log source would reveal on its own.
How does an investigator use SIEM data during forensic reconstruction of an incident?+
Analysts query the correlated event timeline the SIEM has already assembled to establish sequence and scope, such as which systems an attacker touched and in what order, rather than manually cross-referencing raw logs from each system.
Does having a SIEM deployed guarantee an incident will be detected?+
No, detection depends on the correlation rules and log sources actually configured, so gaps in log coverage or poorly tuned rules can let genuine incidents pass through undetected even with a SIEM in place.
Related terms
- Alert Triage
- The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert...
- Binary Log (Database)
- A database engine's sequential record of all committed data modification statements, used primarily for replication and point-in-time recovery. In MySQL and MariaDB,...
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Combined Log Format
- An extension of the Common Log Format used as the default by Apache HTTP Server and widely adopted by Nginx. Adds referrer...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Log Correlation
- The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID....
- Log Rotation
- The scheduled process of closing the current log file, compressing it, renaming it with a date or sequence suffix, and opening a...
- Normalisation
- The process of converting log data from different vendors and formats into a common schema so that fields can be compared across...
- Retention Policy
- An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and...
- Syslog (RFC 5424)
- A standard protocol and message format for transmitting log data from Unix-like systems and network devices to a centralised collector. Each message...
Explained in these topics
- Log Correlation and SIEM in Forensic InvestigationsSecurity Information and Event Management. A platform that aggregates log and event data from across an environment, normalises it, and applies correlation rul...
- Server and Application Log Analysis