
THREAT‑WATCH
Glossary
SIEM (Security Information and Event Management)
A platform that aggregates and correlates log and event data across an organization to support threat detection and compliance reporting.
SIEM tools centralize logs from firewalls, servers, applications, and other systems, then apply correlation rules to surface potentially malicious patterns. A SIEM alone generates alerts; it takes a team (in-house or via MDR) to actually investigate and respond to what it surfaces.