TechKnowSurge
NIST NICE K1269 NIST 800-53 SI-4 CompTIA Security+ 4.4 CompTIA CySA+ 1.1 NIST CSF DE.AE-03 NIST 800-53 AU-2 CompTIA Security+ 4.9
VideoSecurityFree

Security Information and Event Management (SIEM)

A Security Information and Event Management (SIEM) system centralizes security logs and event data from across an infrastructure into a single, access-controlled platform. Keeping it isolated from other monitoring tools prevents insider threats from manipulating security records.

Complete this video to capture a CTF flag worth 1 point.

About this video

A SIEM system is a dedicated platform that aggregates security logs and event data from across an organization's entire infrastructure into a single, centralized location. Because general-purpose monitoring tools — such as log aggregators, network monitors, and database monitors — are accessible to a broader set of users including developers and operations staff, they cannot be relied upon as authoritative security records. A SIEM addresses this by operating outside of those shared systems, with strictly limited access controls that prevent non-security personnel from viewing or modifying its contents. This separation is critical for defending against insider threats, where a malicious actor with access to security logs could alter or delete evidence of their activity. The SIEM collects data from a wide range of sources, including agents installed on endpoints, firewall logs, and network flow data, pulling everything together so that all security-relevant activity across the infrastructure is visible in one place. When a security event or incident occurs, analysts can turn to the SIEM as a trusted, comprehensive record to trace activity, identify affected systems, and support an effective response.

What you'll learn

What's covered

SIEM Systems

Aligned to

NIST NICE
K1269 Knowledge of security information and event management (SIEM) tools and techniques
NIST 800-53
SI-4 System Monitoring
AU-2 Event Logging
CompTIA Security+
4.4 Explain security alerting and monitoring concepts and tools
4.9 Given a scenario, use data sources to support an investigation
CompTIA CySA+
1.1 Explain the importance of system and network architecture concepts in security operations
NIST CSF
DE.AE-03 Information is correlated from multiple sources

Key terms

Security Information and Event Management
SIEM
A system that aggregates and analyzes security event data from across an organization to detect and respond to threats.
Log Management
The process of collecting, storing, analyzing, and monitoring log data generated by systems and applications.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.

Topics

Siem Log Aggregation Security Monitoring Insider Threat Prevention Cybersecurity Event Management

Transcript

One thing we're going to want to set up within our network so we can monitor security is a security information and event management system, or a SIEM.

Why Security Monitoring Sits on Its Own

Within our infrastructure, we're probably going to have a lot of different monitoring systems. One of the things is that there's going to be a lot of people who have access to all of these systems. We want one system to be separate from everything else, and that's going to be the security system.

The problem is that if something goes awry with our system, and maybe we're having issues on our applications, that means that everybody needs to start digging in and figuring out what's going wrong with it, to include probably the developers. There's a good chance that the developers are going to need to have access to troubleshooting tools like the log aggregation, or they might need some sort of network monitoring or database monitoring information, so they need access to all that for troubleshooting purposes.

We don't want to give them access to security, and the reason why is because they might be causing some sort of problems inside the system and maybe want to cover their tracks. Maybe it's some insider threat, and so if they have access to the security logs they can go and manipulate that. It needs to be a system outside of everything else.

What the SIEM Does

So we have a separate system that monitors security information and security event. We have this SIEM system. The SIEM system sits outside of all of the other systems and monitors things from a security aspect, and all of our security logging and all of our security side of things go into this system right here. We have limited access on who gets access to that system and is able to see that information.

This is going to give insight across all of our infrastructure. We'll have devices that are reporting into it. If this is the SIEM server right here, then they report into this. There might be clients that we install on end machines so that way we can gather information that will be logged here, or perhaps it's pulling from other security logs and other sources that are within our network. Firewall logs perhaps, some of our NetFlow information is going into there. It's going to pull from all of these different sources and add it to one location, so now if we have a security event or a security incident we can go up here and start doing research on this server to figure out what's going on.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →