SIEM
Security Information and Event Management
Sicherheitsinformations- und Ereignis-Management
A SIEM centrally collects, normalises and correlates security-relevant log data from across the technology stack and raises alerts from it. It is the shared data hub for detection, investigation and evidence — from servers and endpoints to network, cloud and applications. Without this central view, security monitoring stays piecemeal and blind to connected attack patterns.
History. The term SIEM was coined by Gartner in 2005, merging two older disciplines: Security Information Management (long-term storage and analysis) and Security Event Management (real-time correlation and alerting). Early systems were expensive, hard-to-run collection points; later generations added behavioural analytics (UEBA), cloud sources and tight coupling to automation.
Facts. Core functions are data collection via agents and interfaces, normalisation into a common schema, correlation through rules and signatures (e.g. in the Sigma — Generic Detection Rule Format (Sigma) format), alerting and tamper-resistant retention for forensics and evidence duties. A SIEM is only as good as its data quality and its rules: without clean source onboarding and maintained use cases, the result is either alert floods or blind spots. Well-known examples include Splunk, Microsoft Sentinel, Elastic Security and the open-source Wazuh — Open Source Security Platform (Wazuh).
Outlook & recommendation. With Network and Information Security Directive 2 (NIS2) and the Critical Infrastructure (KRITIS) requirement for attack-detection systems, SIEM-class visibility becomes effectively mandatory. The real effort, however, lies not in procurement but in operation — continuous tuning, triage and response. That is precisely why many mid-sized organisations move the SIEM into a managed-service operation, as NEOSEC offers within the Extended Security Incident and Event Management (XIEM) model.