IT Glossary



Security Information and Event Management

Gartner defines the security and information event management (SIEM) market by the customer’s need to analyze event data in real time for early detection of targeted attacks and data breaches, and to collect, store, investigate and report on log data for incident response, forensics and regulatory compliance. SIEM technology aggregates event data produced by security devices, network infrastructure, systems and applications. The primary data source is log data, but SIEM technology can also process other forms of data, such as network telemetry. Event data is combined with contextual information about users, assets, threats and vulnerabilities. The data may be normalized, so that events, data and contextual information from disparate sources can be analyzed for specific purposes, such as network security event monitoring, user activity monitoring and compliance reporting. The technology provides real-time analysis of events for security monitoring, query and long-range analytics for historical analysis.


Read reviews of Security Information and Event Management…

Gartner Peer Insights has over 3141 reviews on 28+ vendors in the Security Information and Event Management market. Learn about these companies and these products from IT professionals who have first-hand experience with them.

 


Become a Client

Call us now at:

+1 800-213-4848

or

Contact us online 

Free Research
Discover what 12,000 CIOs and Senior IT leaders already know.
Free Access