Glossary term

SIEM

Security Information and Event Management

Centralized security log aggregation, correlation, and alerting.

acronymSecurity & ComplianceSenior

When you'd see it: Security operations and audits. SIEM tools such as Splunk, Microsoft Sentinel, and QRadar aggregate logs to detect threats.

Why it matters: A SIEM collects and correlates logs from across the organization so a security team can see patterns one system would miss, like a login from one country followed by data access from another. It is the nerve center of threat detection.

Common mistakes: Buying a SIEM and assuming you are now secure. It is only as good as the detection rules tuned into it and the people watching it. Unwatched, it is an expensive log bucket.

Study this in BizTech Primer →