IronSights

Detection & response

Security Information and Event ManagementSIEM

A security platform that aggregates log and event data from across an IT environment, correlates it in real time, and generates alerts when suspicious patterns indicate a potential threat.

Also known asSIEMsecurity information and event management

In plain English

A SIEM is the brain of a security monitoring operation. It collects logs from servers, firewalls, endpoints, and cloud services — thousands of events per second — and uses rules and machine learning to find the needles in the haystack that indicate an attack in progress.

Keep learning

More terms in the IronSights Glossary.