SIEM
Security Information and Event Management
Centralized security log aggregation, correlation, and alerting.
Security & Compliance
When you'd see it: Security operations and audits. SIEM tools such as Splunk, Microsoft Sentinel, and QRadar aggregate logs to detect threats.
Why it matters: A SIEM collects and correlates logs from across the organization so a security team can see patterns one system would miss, like a login from one country followed by data access from another. It is the nerve center of threat detection.
Common mistakes: Buying a SIEM and assuming you are now secure. It is only as good as the detection rules tuned into it and the people watching it. Unwatched, it is an expensive log bucket.
Study this in BizTech Primer →