Glossary Term

SIEM

A security system that collects log and event data from across an organization's systems and analyzes it centrally to detect and alert on threats.

Also known as: Security Information and Event Management

A security system that collects log and event data from across an organization's systems and analyzes it centrally to detect and alert on threats.

SIEM (Security Information and Event Management) refers to both a category of security software and the practice of centralizing log and event data from servers, network devices, and applications into one system for correlation, alerting, and audit reporting. Splunk is one widely used self-hosted SIEM platform; there are others, both self-hosted and managed.

Running a SIEM well is an ongoing operational cost, not a one-time install: tuning alert rules, maintaining log sources, and reviewing findings takes dedicated staff time. That ongoing burden is the usual reason an organization evaluates a managed alternative instead of continuing to run the platform itself.