SIEM — Security Information and Event Management
Definition
A category of security software that aggregates, normalizes, and analyzes log data from across an IT environment to detect threats and support compliance.
Context & Usage
SIEM platforms ingest logs from servers, network devices, firewalls, applications, and cloud services. Real-time correlation rules detect attack patterns. Major SIEMs: Splunk Enterprise Security, IBM QRadar, Microsoft Sentinel, Elastic Security, Sumo Logic. Hardware: SIEM ingest servers need high-IOPS storage (NVMe), 256+ GB RAM, and 10+ GbE network.
Examples
- Splunk Enterprise running on Dell R740xd
- Microsoft Sentinel (cloud-based)
Looking for SIEM hardware?
Pro Disk Network stocks enterprise IT hardware spanning every category. Email sales@prodisknetwork.com with your requirements for a quote.