Technology

SIEM

A platform that centralises log data from across an estate, correlates it, and raises alerts on suspicious patterns.

Definition

SIEM, security information and event management, is a platform that collects log and event data from systems across an organisation, normalises it, correlates events, and raises alerts when patterns suggest malicious activity.

The value of SIEM is correlation across sources. A failed login on one server is noise. The same account failing on forty servers, then succeeding, then reaching a file share it has never touched, is a pattern that no single system can see on its own. SIEM exists to make that visible.

SIEM is frequently confused with SOAR, security orchestration, automation and response. SIEM detects and alerts; SOAR acts on what SIEM found, running automated playbooks such as isolating a device or disabling an account. They are complementary, and many modern platforms bundle both, but the distinction matters when scoping a purchase: buying detection does not buy response.

The common failure is treating deployment as the finish line. An untuned SIEM produces alert volumes nobody can work through, and analysts learn to dismiss it. Value comes from tuning, defining which use cases matter, and having people to act on what it raises. A SIEM with no analyst behind it is expensive logging.

At a glance

Type
Security platform
Also known as
Security information and event management, log correlation platform

How it works

  1. 1

    Collection: logs and events are ingested from servers, endpoints, network devices, cloud services and applications

  2. 2

    Normalisation: differing formats are mapped to a common schema so they can be compared

  3. 3

    Correlation: rules and analytics look for patterns across sources rather than single events

  4. 4

    Alerting: matches are raised to analysts with the supporting context

  5. 5

    Retention: data is stored for investigation and to meet regulatory retention expectations

Key points

  • The value is correlation across sources, not storage of logs
  • SIEM detects; SOAR automates the response to what SIEM finds
  • Tuning determines whether it is useful, because untuned alert volume gets ignored
  • It requires analysts; a SIEM with nobody acting on it is expensive logging
  • It sees system behaviour, so a successful phishing login can look entirely legitimate

Best practices

  • Start from a small number of high-value detection use cases rather than ingesting everything
  • Tune continuously and measure false-positive rate, since analyst trust is the real asset
  • Make sure log sources actually cover the paths an attacker would use, especially identity systems
  • Define who responds to each alert class before go-live
  • Feed staff phishing reports in as a detection source, because people notice things logs do not

Real-world example

An Indonesian bank deploys a SIEM and ingests everything available, generating around 4,000 alerts a day. Analysts triage the top of the queue and ignore the rest. After narrowing to twelve well-tuned use cases, daily alerts fall to roughly 60 and the first genuine account-takeover attempt is caught within a fortnight.

How Claro helps

SIEM sees systems, not intentions, so a successful phishing attack often looks like a legitimate login from a valid credential. Claro reduces the volume of successful phishing reaching that point, and phish-report data from staff gives a detection signal that no log source produces.

Frequently asked questions

What is SIEM in cyber security?

SIEM, security information and event management, is a platform that collects log and event data from across an organisation, normalises and correlates it, and alerts when patterns suggest malicious activity. Its value is seeing patterns that span multiple systems.

What is the difference between SIEM and SOAR?

SIEM detects and alerts; SOAR, security orchestration automation and response, acts on those findings by running automated playbooks such as isolating a device or disabling an account. They are complementary, and buying detection does not automatically buy response.

Does SIEM detect phishing?

Partly. It can surface the consequences, such as a login from an unusual location or unexpected data access after credential theft. It cannot see the deception itself, and a successful phishing login often looks like a legitimate authentication.

Do we need a SOC to run a SIEM?

You need people to act on alerts, whether that is an internal team, a managed service, or named individuals with defined responsibility. A SIEM with nobody triaging its output does not improve security, it just increases logging cost.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo