Security Incident and Event Management (SIEM) enhances the power of a traditional log monitoring tool with the help of co-relation and alerting-based solution.
Co-relation is one powerful feature that makes SIEM a distinguished player.
Let's understand the co-relation part with an example. The user's ID card has been swiped in at the office; however, his ID card was swiped at the datacenter provider as well without having swiped out at the office. This seems suspicious. SIEM will co-relate the two events and can determine that the user cannot be present at both the locations simultaneously and will alert the SOC immediately.
There was a possible port scan from a particular IP address and then there was a possible login attempt to an SSH service running on an ephemeral port. These two events are co-related and need to be alerted...