Skip to content

SIEM

Definition

Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies correlation rules to generate alerts. Examples include Splunk, IBM QRadar, Microsoft Sentinel, and the open-source Wazuh. The primary infrastructure for large-scale log correlation.

Full name
Security Information and Event Management
Function
Ingest, normalise, and correlate log streams
Examples
Splunk, IBM QRadar, Microsoft Sentinel, Wazuh
Output
Correlated alerts across data sources
Sub-field
Digital forensics and incident response

Common questions

Why is a SIEM described as the primary infrastructure for large-scale log correlation rather than just log storage?+

Beyond storing logs, a SIEM normalises data from disparate sources into a common schema and applies correlation rules across them, which lets an analyst spot a multi-stage attack pattern that no single log source would reveal on its own.

How does an investigator use SIEM data during forensic reconstruction of an incident?+

Analysts query the correlated event timeline the SIEM has already assembled to establish sequence and scope, such as which systems an attacker touched and in what order, rather than manually cross-referencing raw logs from each system.

Does having a SIEM deployed guarantee an incident will be detected?+

No, detection depends on the correlation rules and log sources actually configured, so gaps in log coverage or poorly tuned rules can let genuine incidents pass through undetected even with a SIEM in place.

Related terms

Alert Triage
The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert...
Binary Log (Database)
A database engine's sequential record of all committed data modification statements, used primarily for replication and point-in-time recovery. In MySQL and MariaDB,...
Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Combined Log Format
An extension of the Common Log Format used as the default by Apache HTTP Server and widely adopted by Nginx. Adds referrer...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Log Correlation
The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID....
Log Rotation
The scheduled process of closing the current log file, compressing it, renaming it with a date or sequence suffix, and opening a...
Normalisation
The process of converting log data from different vendors and formats into a common schema so that fields can be compared across...
Retention Policy
An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and...
Syslog (RFC 5424)
A standard protocol and message format for transmitting log data from Unix-like systems and network devices to a centralised collector. Each message...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.