A platform that gathers and correlates security logs to detect threats and raise alerts. In Azure the cloud SIEM is Microsoft Sentinel, which runs on a Log Analytics workspace.
Also called security information and event management.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700AI-103DP-750SC-900SC-200SC-300SC-401MD-102DP-800ALZ
Each book explains SIEM in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
Related terms
- Insider Risk Indicators connector
A preview connector in Microsoft Purview that brings in detections already processed and aggregated by other tools, a SIEM for example. These arrive in Insider Risk Management as custom indicators or triggers.
- SOAR
Security orchestration, automation and response: tools that receive alerts from a SIEM and other sources and react to them automatically using workflows known as playbooks. Microsoft Sentinel offers SOAR as well as SIEM.