Comparative Analysis of Open Source Security Information & Event Management Systems (SIEMs)

  • Bezas K
  • Filippidou F
N/ACitations
Citations of this article
28Readers
Mendeley users who have this article in their library.

Abstract

A Security Information and Event Management system (SIEM) is a tool used to collect, analyze, normalize and correlate data from various devices to identify potential cyber threats almost in real-time. SIEM provides a unified approach to security issues through two zones: Security Information Management (SIM) and Security Event Management (SEM). SIM deals with managing logs and reporting, while SEM deals with event management and real-time monitoring. SIEM tools collect data events in a central unit from various devices, normalize their format, analyze them, and generate reports and alerts. SIEM combines the ability of log management to generate a compliance report with the ability to manage threats. However, the central approach may present significant disadvantages, such as slowing system performance and complicating the prioritization of queries.

Cite

CITATION STYLE

APA

Bezas, K., & Filippidou, F. (2023). Comparative Analysis of Open Source Security Information & Event Management Systems (SIEMs). The Indonesian Journal of Computer Science, 12(2), 443–468. https://doi.org/10.33022/ijcs.v12i2.3182

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free