SIEM
/sɪm/ · Abbreviation · Security & Infosec · Origin: 2005
Definitions
Security Information and Event Management — a system that aggregates log data from across an organization's infrastructure, correlates events, and alerts analysts to potential security incidents.
In plain English: A central dashboard that collects security alerts from all your systems and tries to spot patterns that indicate an attack.
Etymology
- 2005
- Gartner analyst Mark Nicolett coins 'SIEM' (Security Information and Event Management), merging two existing categories (SIM + SEM)
- 2012
- Splunk IPOs at $1.6B, validating SIEM as a major software category
- 2020s
- Cloud-native SIEMs and AI-driven triage attempt to solve the signal-to-noise problem that has plagued SIEMs since inception
Related Terms
- SOC
- Incident Response
- Observability
- Postmortem
- Audit Log
- Attack Surface Management
- Audit Trail
- Cloud Security Posture Management
- CSPM
- Data Loss Prevention
- Deep Packet Inspection
- DLP
- File Integrity Monitoring
- Log Correlation
- Log Management
- Security Information and Event Management
- SOAR
- Syslog
- Access Log
- Alert Fatigue
- Database Activity Monitoring
- Honeynet
- Log Monitoring
- Log Pipeline
- Managed Detection and Response
- MDR
- MSSP