Skip to content

SIEM (Security Information and Event Management)

Definition

A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates alerts, and produces reports. Common platforms include Splunk, Microsoft Sentinel, IBM QRadar, and the open-source Elastic SIEM.

Function
Aggregates and correlates log/event data across an environment
Outputs
Alerts and reports from detection rules
Common platforms
Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM
Forensic role
Central source for reconstructing a timeline across systems

Common questions

How does a SIEM support forensic investigation rather than just alerting?+

Because it centralises logs from many systems in one searchable place, an investigator can query the SIEM after an incident to reconstruct a timeline across hosts, network devices, and applications that would otherwise require pulling and correlating logs manually from each system.

What is a common limitation of relying on SIEM data during an investigation?+

A SIEM only retains what its log sources send it, for as long as its retention policy allows. If a system was not forwarding logs before the incident, or logs rolled off before retention was extended, that activity is simply not recoverable from the SIEM.

Related terms

EDR (Endpoint Detection and Response)
An agent-based security tool deployed on individual endpoints (workstations, servers, mobile devices) that monitors process execution, file changes, network connections, and registry...
Alert Correlation
The process of grouping multiple related events or alerts into a single higher-level alert representing one attack sequence. A correlation rule might...
Alert Fatigue
The condition in which analysts receive more alerts than they can meaningfully review, leading to delayed responses, dismissed true positives, and reduced...
Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Compliance Dashboard
An automated reporting surface that aggregates metric and control-status data and presents it in a format aligned to one or more regulatory...
Continuous Monitoring
An automated control framework that applies fraud indicator tests to transactions as they are processed or on a frequent scheduled basis, generating...
Control Effectiveness
The degree to which a security control achieves its intended objective under real operating conditions. Measured through a combination of design review...
Escalation Path
The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
Hypothesis Testing
In digital forensics, the practice of forming a specific, falsifiable proposition about what occurred (such as 'the attacker used account X to...
IDS/IPS (Intrusion Detection/Prevention System)
Network or host-based systems that inspect traffic or system calls for known attack patterns. An IDS generates alerts without blocking; an IPS...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Key Performance Indicator (KPI)
A metric that measures how well a specific control or process is performing against a defined target. KPIs are often lagging indicators:...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.