<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Logging on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/logging/</link><description>Recent content in Logging on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/logging/index.xml" rel="self" type="application/rss+xml"/><item><title>SIEM (Security Information and Event Management)</title><link>https://lesitedefrancois.be/en/security/siem/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/siem/</guid><description>&lt;p&gt;&lt;strong&gt;SIEM (Security Information and Event Management)&lt;/strong&gt; is a platform that aggregates security telemetry from across an organisation&amp;rsquo;s infrastructure, normalises it into a common schema, applies correlation rules and behavioural analytics to detect threats, and retains the data for investigation and compliance reporting. The name combines two earlier disciplines: &lt;strong&gt;SIM (Security Information Management)&lt;/strong&gt; — long-term log retention, compliance reporting, and forensic search — and &lt;strong&gt;SEM (Security Event Management)&lt;/strong&gt; — real-time alert correlation and incident detection. Modern SIEMs do both simultaneously, serving as the primary visibility layer for a Security Operations Centre (SOC). Leading platforms include Splunk Enterprise Security, IBM QRadar, Microsoft Sentinel, Elastic Security, Exabeam, and LogRhythm; all share the same fundamental architecture despite differing in query language (SPL for Splunk, KQL for Sentinel, EQL/KQL for Elastic, AQL for QRadar), correlation engine design (search-based vs dedicated CEP engine), and deployment model (on-premises, SaaS, or hybrid).&lt;/p&gt;</description></item></channel></rss>