Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
Enter your email address below and subscribe to our newsletter

Adopting or changing a security information and event management platform is one of the more impactful technology decisions for a security team. Because SIEM plays such a central role in a security operations program, providing detection, investigation, compliance and reporting capabilities (its arguably the Architecture DNA in the big picture) it means that deploying a poor fit will create compounding problems that are costly to unwind. Evaluating well about what those technologies actually do, and what differentiates from effective platforms versus poor ones, you have to understand any of this first.
In this article, I will go through the primary functionalities of SIEM software, the technical capabilities that determine platform quality, and the evaluation criteria to pay attention to when comparing options in an increasingly diverse market.
Organizations at the stage of evaluating platforms for their environment can reference SIEM software for log analysis to understand how modern solutions approach the core functions of ingestion, normalization, and detection at enterprise scale.
One of the main purpose of any SIEM is extracting log and events data from sources spanning the whole environment. These include OS event logs, firewall and network device logs, endpoint telemetry, application logs, identity and access management records and cloud service audit trails. The platform constantly collects these streams available and saves them in a central area that can be queried by analysts.
Please note that raw log data from various sources comes in different formats, different field names, timestamp7 and way of representing the same events differently. The SIEMs are designed in a way that their normalization is the process where they convert this heterogeneous data into a standardized schema and allow you to write some detection rules and execute some queries over the all data sources at once rather than using individual logic against each and every source.
The platform learns correlation logic on the normalized data and finds events to pay attention to. When event A occurs within a defined time frame after B, or if across 2 (or many) systems in the same period of time an account appears across events, correlation rules instructs the platform to create an alert that takes into account the additive weight of these inputs rather than treating each as an independent data point.
Detection does not stop at rule-based correlation on modern platforms. Unlike rule-based systems, behavioral analytics create a baseline profile for users, accounts and/or systems and alert on deviations away from those baselines. Correlation can be enhanced by threat intelligence integration, which matches observed indicators against known bad infrastructure, tactics, and techniques from external feeds.
Analysts must have context in order to assess an alert when it is generated. And SIEM platforms provide that context by making the raw log data queryable and allowing events to be displayed in a timeline view to highlight what occurred prior to and after the triggering event. Good platforms support the ability for analysts to move from an alert to the full universe of activity around that user, IP address, or asset without rewriting the query.
This functionality is then taken one step further by many platforms, and broken into structured case management audiences receive alerts but are promoted to incidents where they are assigned to analysts, tracked through investigation stages, and documented for review after an incident. By integrating investigations into this workflow, using multiple tools becomes more manageable.
Regulations for various regulations dictate organizations should prove they are maintaining access monitoring both to sensitive systems; keep audit logs for designated periods; and detect and document incidents. The role of a SIEM platform serves this job by retaining the log information that compliance audits rely on and by making reports executed with and to different frameworks, like PCI DSS, HIPAA, and SOX. Automated compliance reporting leads to less manual work in each audit cycle and has a homogenous, auditable trail.
National standards for how organizations should approach continuous monitoring of security controls and deployed systems are documented in guidance from the National Institute of Standards and Technology, including the framework outlined in the publication on continuous monitoring security controls for federal and private sector environments alike.
The critical first question of any SIEM evaluation: can the platform ingest data from all sources important to the organization? A platform that excels at common Windows event logs and leading network device vendor support but lacks coverage of cloud service providers, SaaS applications, or OT environments will miss the visibility needed to realize your investment value.
Consider not just which types of sources are supported, but how they are supported (native connectors that log data normalized out-of-the-box vs. manual log forwarding with custom parsing work) as these represent significantly different operational slopes. Do not make the leap that coverage is done on all sources, especially if they are in uncommon or proprietary domains of the organization.
The detection content a platform ships with out-of-the-box is a good starting point, but the more important evaluation criterion is how well the platform enables continuous tuning. Default correlation rules are generic patterns that can be scripted and will cause massive noise when applied to any specific organization infrastructure. A key requirement to ensure you keep the alert volume at a manageable level is the ability to create, edit and disable rules independently of your vendor over time.
The capability of behavioral analytics solutions should also be assessed on the strength of the baseline modeling, as well as clarity around anomaly scoring. Certain platforms that churn out large amounts of low-confidence behavioral alerts but without clarifying what led to the score are building a type of noise problem that correlation tuning aims to remedy.
The SIEM is quite vital during an active investigation, but the real value comes from how quickly the platform can return results as well as how easy it is for analysts to query against large volumes of historical data without getting bogged down while working under time-crunches. An all-or-nothing platform that is 100% coverage with solid detection logic but returns queries slowly or where the query language requires specialists to write, will hinder investigative quality at the times you most need.
Test the search performance with realistic data volumes and not demo sized environments that are used for demos. Ask for an opportunity to deploy running, time-boxed proof-of-concept against real logs from the organizations environ before deciding on-place.
See also: Fashion Product Developer and Tech Designers
SIEM platforms do not exist in a vacuum. They consume data from endpoint detection tools, identity platforms, network sensors and vulnerability scanners – and export enriched alerts to ticketing systems, response automation platforms and reporting infrastructure. The degree of friction in the overall security operations workflow is determined by the depth and quality of these integrations.
For platforms with well-documented APIs, all of which have been progressively integrated over time across the standard classes of security tools there will be a help reduction for solutions with ubiquitous integration rather than needing custom development for every individual connection.
The log volume in enterprise environments increases with time as more and more data sources are linked to the SIEM and cloud adoption spreads. Understand how the platform scales with increased data volume for both ingestion and queries, and know the pricing model according to that growth. Data ingestion based pricing models will create large shocks in cost when the environment scales, while flat-rate or capacity-based models afford greater predictability of spend.
A thorough review of the market for platforms that address different scale and functional requirements, including how they compare across deployment models and key feature areas, is available through IT analyst coverage on security software selection guide resources that assess options across the enterprise range.
SIEM solutions pull together log and event data from across an organization, normalizing it into a common format, and runs correlation and behavioral analytics to pinpoint behavioral patterns to detect potential security threats. It retains audit log data and generates reports aligned with frameworks to support compliance reporting, and it gives analysts the investigative context needed to assess whether alerts are real or false positives successfully.
After data sources are connected, basic compliance reporting and detection coverage from default rules is easily achievable. Relevant threat detection customized for the organizational context generally requires multiple months of continual rule refinement and baseline calibration. Until the platform runs at its maximum capability, organizations need to plan for a maturation period and reserve analyst bandwidth to tune.
SIEM differentiates itself by integrating a centralized aggregation of logs across all source types with cross-source correlation logic, long retention windows and compliance reporting. Deep into the details, endpoint detection only works on endpoints. Network detection tools work only on network traffic. SIEM fuses information from every one of those sources and gives a solitary stage to discovering, investigating, and reporting over the whole climate.