SIEM
Security Information and Event Management (SIEM) software works by collecting log and event data that is generated by host systems, security devices and applications throughout an organization’s infrastructure and collating it on a centralized platform. From antivirus events to firewall logs, SIEM software identifies this data and sorts it into categories, such as malware activity, failed and successful logins and other potentially malicious activity.
- common industries- finance, insurance, retail, government, infrastructure, health care
- top vendors- McAfee, Elastic, Rapid7, QRadar