Security Information and Event Management
Full Name
SIEM = Security Information and Event Management
Originally this term was applied to data collection about the security state and events in an enterprise. It has since broadened to cover pro-active security state determination and remediation of cyber threats as well, although often under a wide variety of different names.
Context
Web sites have long kept logs of incoming HTTP traffic to diagnose web site problems.
References
- Wikipedia page on SEIM
- Connect to the Intelligent Security Graph using a new API is a Microsoft variant for the Azure cloud current as of 2018-04-17.
- Collect and consume log data from your Azure resources
Solutions
Gartner Magic Quadrant
The companies that were in the visionary half of the 2021 chart were ranked in the following order.
Vendor | Cloud | AI | Location | Notes |
Exabeam | user and entity behavior analytics | SV CA | ||
IBM QRadar | Watson | separate division | everywhere | |
Securonix | AWS | forbes article | TX & India | |
Splunk | open source | comodo is one provider | NJ | |
Rapid7 | SF CA | |||
Logrythm | ||||
Gunucul | ||||
Microsoft | ||||
Sumo Logic | ||||
Fortnet |
The leader of the field in longevity is ArcSight by Microfocus (after merger from HP) which is rather poorly rated by Gartner. They were the ones who identifier the problem for the customer as "too much data" back in 2001. Microfocus targets legacy infrastructure.