SIEM

Security Information and Event Management (SIEM) centrally collects and correlates logs and security events from many sources. The platform makes them available for detection, compliance and forensics.

Context

A SIEM is the classic detection and compliance foundation. Modern environments increasingly complement or replace SIEM with XDR platforms. A SOC operates the platform; see SOC as a Service Switzerland. For the full comparison see SOC vs. SIEM and MDR vs. Managed SIEM.

Related terms

    Want to see this term in a real SOC context? Talk to us →