SIEM
A platform that centralises log data from across an estate, correlates it, and raises alerts on suspicious patterns.
Definition
SIEM, security information and event management, is a platform that collects log and event data from systems across an organisation, normalises it, correlates events, and raises alerts when patterns suggest malicious activity.
The value of SIEM is correlation across sources. A failed login on one server is noise. The same account failing on forty servers, then succeeding, then reaching a file share it has never touched, is a pattern that no single system can see on its own. SIEM exists to make that visible.
SIEM is frequently confused with SOAR, security orchestration, automation and response. SIEM detects and alerts; SOAR acts on what SIEM found, running automated playbooks such as isolating a device or disabling an account. They are complementary, and many modern platforms bundle both, but the distinction matters when scoping a purchase: buying detection does not buy response.
The common failure is treating deployment as the finish line. An untuned SIEM produces alert volumes nobody can work through, and analysts learn to dismiss it. Value comes from tuning, defining which use cases matter, and having people to act on what it raises. A SIEM with no analyst behind it is expensive logging.
At a glance
- Type
- Security platform
- Also known as
- Security information and event management, log correlation platform
How it works
- 1
Collection: logs and events are ingested from servers, endpoints, network devices, cloud services and applications
- 2
Normalisation: differing formats are mapped to a common schema so they can be compared
- 3
Correlation: rules and analytics look for patterns across sources rather than single events
- 4
Alerting: matches are raised to analysts with the supporting context
- 5
Retention: data is stored for investigation and to meet regulatory retention expectations
Key points
- The value is correlation across sources, not storage of logs
- SIEM detects; SOAR automates the response to what SIEM finds
- Tuning determines whether it is useful, because untuned alert volume gets ignored
- It requires analysts; a SIEM with nobody acting on it is expensive logging
- It sees system behaviour, so a successful phishing login can look entirely legitimate
Best practices
- Start from a small number of high-value detection use cases rather than ingesting everything
- Tune continuously and measure false-positive rate, since analyst trust is the real asset
- Make sure log sources actually cover the paths an attacker would use, especially identity systems
- Define who responds to each alert class before go-live
- Feed staff phishing reports in as a detection source, because people notice things logs do not
Real-world example
An Indonesian bank deploys a SIEM and ingests everything available, generating around 4,000 alerts a day. Analysts triage the top of the queue and ignore the rest. After narrowing to twelve well-tuned use cases, daily alerts fall to roughly 60 and the first genuine account-takeover attempt is caught within a fortnight.
How Claro helps
SIEM sees systems, not intentions, so a successful phishing attack often looks like a legitimate login from a valid credential. Claro reduces the volume of successful phishing reaching that point, and phish-report data from staff gives a detection signal that no log source produces.
Frequently asked questions
What is SIEM in cyber security?
SIEM, security information and event management, is a platform that collects log and event data from across an organisation, normalises and correlates it, and alerts when patterns suggest malicious activity. Its value is seeing patterns that span multiple systems.
What is the difference between SIEM and SOAR?
SIEM detects and alerts; SOAR, security orchestration automation and response, acts on those findings by running automated playbooks such as isolating a device or disabling an account. They are complementary, and buying detection does not automatically buy response.
Does SIEM detect phishing?
Partly. It can surface the consequences, such as a login from an unusual location or unexpected data access after credential theft. It cannot see the deception itself, and a successful phishing login often looks like a legitimate authentication.
Do we need a SOC to run a SIEM?
You need people to act on alerts, whether that is an internal team, a managed service, or named individuals with defined responsibility. A SIEM with nobody triaging its output does not improve security, it just increases logging cost.
Related terms
Security Operations Center
The team and function responsible for monitoring, detecting and responding to security events, often around the clock.
Incident Response
The structured process an organization follows to detect, contain, investigate, and recover from a security incident.
Attack Surface
The total set of points, technical and human, where an attacker could attempt to gain entry to a system or extract data, including every account, endpoint, application, exposed service, and employee.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo