SECURITY

SIEM

A platform that ingests logs and events from across your environment, correlates them, and surfaces detections for analysts.

IN PRACTICE

Splunk, Sentinel, Chronicle, Elastic, all SIEMs. A SIEM without tuned detections and a team watching it is an expensive log archive.

← Back to glossary