Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a SIEM?

A security information and event management platform, or SIEM, collects events from many systems for searching, correlation, monitoring and alerting. It is usually an analytical copy and transformation layer, not the original source.

Collection makes diverse records searchable together

Devices, servers, cloud services, identity platforms and security products send data through agents, connectors or APIs. The SIEM parses fields into a common schema, may convert time, and can enrich records with user, asset or threat information.

This enables cross-system timelines and pattern searches. It also means the displayed event may combine source content with parser decisions and later context.

Coverage and transformation limit the view

A source may never have been connected, collection may fail, parsers can mis-map fields and retention can expire. Identify the originating system and whether the SIEM entry is raw, parsed, enriched, correlated or summarised.

Preserve the query, filters, export and time-zone settings. Where field meaning or evidential precision matters, compare the SIEM representation with the source record and collection configuration. A central dashboard is useful, but neither complete nor infallible by default.

The point to remember

A SIEM helps find and connect events, while source coverage, parsing, enrichment and retention determine what its view can prove.

Reference: LOG-101Logs, Records & Provider Evidence