A Security Information and Event Management (SIEM) system centralizes security logs and event data from across an infrastructure into a single, access-controlled platform. Keeping it isolated from other monitoring tools prevents insider threats from manipulating security records.
SIEM Systems
One thing we're going to want to set up within our network so we can monitor security is a security information and event management system, or a SIEM.
Within our infrastructure, we're probably going to have a lot of different monitoring systems. One of the things is that there's going to be a lot of people who have access to all of these systems. We want one system to be separate from everything else, and that's going to be the security system.
The problem is that if something goes awry with our system, and maybe we're having issues on our applications, that means that everybody needs to start digging in and figuring out what's going wrong with it, to include probably the developers. There's a good chance that the developers are going to need to have access to troubleshooting tools like the log aggregation, or they might need some sort of network monitoring or database monitoring information, so they need access to all that for troubleshooting purposes.
We don't want to give them access to security, and the reason why is because they might be causing some sort of problems inside the system and maybe want to cover their tracks. Maybe it's some insider threat, and so if they have access to the security logs they can go and manipulate that. It needs to be a system outside of everything else.
So we have a separate system that monitors security information and security event. We have this SIEM system. The SIEM system sits outside of all of the other systems and monitors things from a security aspect, and all of our security logging and all of our security side of things go into this system right here. We have limited access on who gets access to that system and is able to see that information.
This is going to give insight across all of our infrastructure. We'll have devices that are reporting into it. If this is the SIEM server right here, then they report into this. There might be clients that we install on end machines so that way we can gather information that will be logged here, or perhaps it's pulling from other security logs and other sources that are within our network. Firewall logs perhaps, some of our NetFlow information is going into there. It's going to pull from all of these different sources and add it to one location, so now if we have a security event or a security incident we can go up here and start doing research on this server to figure out what's going on.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →