Skip to main content

IT security

What is SIEM?

SIEM collects log data from your entire IT environment and raises the alarm on suspicious activity. Understand how a SIEM works, and when it makes sense.

In short

SIEM stands for Security Information and Event Management and is a system that collects log data from your entire IT environment, correlates the events and triggers alerts when something looks suspicious.

Where a firewall or an antivirus program looks at one area at a time, a SIEM assembles the picture across servers, networks, cloud services and user accounts, so attacks can be detected while they are in progress. The system is relevant for businesses that want to detect security incidents quickly, and for organisations with compliance requirements such as NIS2, where logging and incident handling must be documented.

The key points are that a SIEM is only a tool, that its value depends on which log sources you connect, and that someone has to act on the alerts, typically a SOC. Modern cloud-based solutions such as Microsoft Sentinel have made the technology accessible to smaller organisations. MI Support IT helps Danish businesses choose, implement and run a SIEM solution that matches their size and risk profile.

Back to the glossary

What is SIEM?

SIEM (Security Information and Event Management) is a system that gathers log data from the entire IT environment in one place and analyses it for signs of attack. Every single system in your business already logs today: the server records logins, the firewall records traffic, and the cloud services record who accesses what. The problem is that no one can manually keep track of thousands of scattered log files. A SIEM solves this by collecting, normalising and cross-referencing all the events, so patterns emerge that no individual system would ever catch on its own.

How does a SIEM work?

A SIEM system works in three steps:

  1. Log collection: agents and integrations send log data from servers, clients, network equipment, SaaS services and identity platforms such as Microsoft Entra ID into one central platform.
  2. Correlation: rules and machine learning cross-reference events across sources. One failed login is noise; twenty failed logins followed by a successful login from a new country and a large file download is a pattern.
  3. Alerts: when a pattern matches a rule, an alert is created with context, so an analyst can quickly assess whether it is a real attack.

The same log data also serves as your documentation for compliance requirements such as NIS2, where you must be able to demonstrate what happened during an incident.

SIEM vs. SOC vs. EDR

The terms are related, but each covers its own ground:

  • SIEM is the tool that collects and correlates log data from the entire environment.
  • SOC is the team of people who monitor the alerts and respond to them. A SIEM with no one watching it delivers limited value.
  • EDR is the specialised protection on the devices themselves, that is, computers and servers. EDR is typically one of the most important log sources feeding into a SIEM.

A mature security setup combines all three: EDR catches the detail on the device, SIEM assembles the big picture, and the SOC acts on it.

Microsoft Sentinel as a cloud SIEM

Traditional SIEM systems required their own servers and heavy maintenance. Cloud-based solutions have changed that. Microsoft Sentinel runs in Azure, scales with the data volume and has ready-made integrations for Microsoft 365, Microsoft Defender and hundreds of third-party sources. Microsoft's own documentation describes the architecture in detail. For businesses already in the Microsoft ecosystem, Sentinel is often the shortest route to a working SIEM solution, but the principle is the same regardless of vendor: Splunk, Elastic and other platforms solve the same task. Read more about the product on our Microsoft Sentinel page.

How MI Support IT can help

We help you assess whether a SIEM makes sense for your size and risk profile, choose the right platform, connect the log sources that actually matter, and set up alerts that someone acts on. All of it as part of a comprehensive approach to IT security. Contact us for a no-obligation conversation about monitoring your environment.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.