Also known as: SIEM Data Quality, Telemetry Quality
The completeness, accuracy, timeliness, consistency, and context of the telemetry a SIEM uses for detection and investigation.
Security data quality describes whether the records reaching a SIEM are complete, correctly parsed, timely, consistently mapped, and rich enough to support a defensible conclusion.
Common failures include missing sources, delayed events, incorrect timestamps, lost user or asset identity, malformed fields, duplicate records, and generic message strings that hide the original event structure.
AI does not remove the data-quality requirement. A fluent summary built from incomplete or incorrectly mapped telemetry is still wrong.