SaveMyCert
Cloud basics

What is a SIEM? Security information and event management

A SIEM, short for Security Information and Event Management, is a system that collects, correlates and analyses log and event data from across an organisation’s systems to detect threats and raise alerts in one place. Every server, application, firewall and cloud service writes its own records, and no person can read them all. A SIEM brings them together so patterns that look harmless in one log become obvious across many. This article covers the problem it solves, what it actually does, its role in a security operations centre, and how it relates to monitoring and observability.

The problem a SIEM solves

A SIEM solves the problem of scattered, overwhelming logs. Each system records what happens to it: logins, errors, blocked connections, configuration changes. Spread across dozens or hundreds of sources, those records are far too many to read, and an attacker’s trail is split across them in small pieces. One failed login means little; a failed login on one system followed by a success from the same address on another, then an unusual data transfer, is a story. A SIEM lets you see that story in one place.

What a SIEM does

The name describes two jobs, managing information and managing events, and in practice a SIEM works through four steps:

  1. Aggregate — collect logs and events from servers, applications, network devices, identity systems and cloud services, and normalise them into a common format.
  2. Correlate — link related events across sources, using rules or analytics, to spot suspicious patterns that no single log shows.
  3. Alert — raise a prioritised alert when something matches a threat pattern, so people look at the important signals first.
  4. Support investigation — keep searchable history so analysts can trace what happened, when, and which systems were touched.

Its place in a security operations centre

A security operations centre, or SOC, is the team that watches for and responds to threats, and the SIEM is usually its main working tool. Analysts triage the alerts it raises, investigate the real ones, and pass confirmed incidents on to be handled. That hand-off is the subject of our what is incident response explainer, and the two are best read together: the SIEM tells you something is wrong, and incident response is what you do about it.

SIEM, monitoring and observability

Monitoring and observability are mainly about whether systems are healthy and performing, while a SIEM is mainly about whether they are being attacked or misused. They use similar raw material, logs and metrics, but ask different questions, and the tooling often overlaps. Our what is observability explainer covers the operational side. A SIEM is also not a silver bullet: it is only as good as the data fed into it and the rules tuned by people, and too many poor alerts simply tire the team out.

Where it fits in cloud security and study

In the cloud, a SIEM ingests provider activity logs and service logs alongside everything else, supporting the monitoring and threat-detection pillar of cloud security, which our what is cloud security article sets out. Penetration tests, covered in our what is penetration testing explainer, are a good way to find out whether your SIEM would actually notice an attack. Our /revision library covers security monitoring in the ISC2 Certified in Cybersecurity and AWS Certified Security – Specialty syllabuses lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SOA-C03SCS-C03CC

Questions, answered

SIEM stands for Security Information and Event Management. It is a system that gathers log and event data from many sources, correlates it to find suspicious patterns, and raises alerts so security teams can investigate from one place.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is incident response? The lifecycle explained
Cloud basics
What is malware? Types, how it spreads and how to defend
Cloud basics
What is penetration testing? Ethical hacking explained
Cloud basics
What is phishing? How it works and how to spot it