Introduction to SIEM
Many security compliance standards require long-term storage, where security-related logs should be kept for long periods of time. This varies from one compliance standard to another and can be up to many years. This is where SIM comes into the picture: long-term storage where all security-related logs are stored for analysis and reports.
When we speak of SEM, we tend to be talking about live data streaming rather than long-term event tracking. SEM's focus is on real-time monitoring; it aims to correlate events using notifications and dashboards. When we combine these two, we have SIEM, which tries to live stream all security-related logs and keep them for the long term. With this approach, we have a real-time monitoring and reporting tool in one solution.
When discussing the functionalities required, we have a few checkboxes that SIEM must tick:
- Data aggregation: Logs across different systems are kept in a single place. This can include network...