Skip to main content

Security Information and Event Management (SIEM)

Security information and event management collects, normalizes, stores, searches, and correlates security-relevant event and log data from multiple sources.

What is Security Information and Event Management (SIEM)?

Security information and event management collects, normalizes, stores, searches, and correlates security-relevant event and log data from multiple sources. It gives analysts shared views and alerts for detection, investigation, and reporting. Some analysis can occur near real time, but collection and detection delays still exist. A SIEM supports decisions. It does not prove that every alert is an incident or perform complete response by itself.

Why it matters

One event often has little meaning on its own. A SIEM can connect identity, endpoint, network, cloud, and application events so an analyst can find a pattern and preserve evidence for an investigation.

How it works

  1. Collectors receive events from security and application sources, normalize fields, and add useful time and identity context.
  2. The SIEM stores and indexes the events, then applies searches, rules, and analytics across the combined data.
  3. Analysts investigate alerts, start response actions, preserve evidence, and tune detections from the results.

Example

A SIEM correlates repeated denied Pomerium requests for one user with an identity-provider change and alerts an analyst to review the account.

Pomerium boundary

Pomerium emits structured proxy access logs and authorization logs with request and policy-decision fields. Operators can collect those logs in a SIEM for correlation and investigation. Pomerium does not replace the SIEM ingestion, retention, detection, or response workflow.

Limits and non-claims

  • Missing sources, clock errors, dropped events, and inconsistent field parsing create detection gaps.
  • Correlation rules and analytics can produce false positives and false negatives, so they need testing and tuning.
  • Central logs can contain sensitive data and need access control, integrity protection, retention rules, and capacity planning.

Evaluation checklist

  • Which identity, policy, resource, action, time, and outcome fields reach the SIEM with integrity?
  • Which detection or investigation question can each normalized event answer?
  • How do missing telemetry, clock error, noise, tampering, and ingestion failure appear to responders?

Sources and further reading

Keep learning

Security Operations and Risk

Intrusion Detection

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.

Learn this term
Security Operations and Risk

Data Breach

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.

Learn this term
Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo