SIEM
SIEM is a security information and event management system that collects and correlates logs from many sources to detect threats in real time.
Stands for: Security Information and Event Management
SIEM emerged in the mid-2000s from the merger of security information management (SIM: long-term storage and reporting) and security event management (SEM: real-time monitoring and alerting). It gathers logs from firewalls, routers, servers, identity systems, endpoint protection and cloud services into a single platform.
The core workflow has four steps. Logs are collected via syslog, agents or APIs. Messages in different formats are converted into a common schema (normalisation). Events are correlated with rules, for example many failed logins in a short time followed by a successful login and unusual outbound data transfer. Finally, alerts, dashboards and compliance reports are produced. Current solutions also offer user and entity behaviour analytics (UEBA), threat intelligence feeds and SOAR integrations that automate incident response.
SIEM capacity is usually measured in events per second (EPS) and daily data volume, and licence and hardware costs scale accordingly. The most common mistake is sending every log without first defining which threats should be detected. This inflates cost and leads analysts to miss real incidents among false positives (alert fatigue). Mapping use cases to frameworks such as MITRE ATT&CK and tuning rules regularly is recommended.
A SIEM is a layer built on top of central log management. Raw logs have to be collected and retained completely, with accurate timestamps and in tamper-evident form. Reliable correlation depends on that, and so do the data security measures and breach investigations required under KVKK.
Have a project in mind?
Tell us briefly what you want to set up, or give us a call. We'll pass it to the right team.
