Security Information and Event Management

Adam Tilmar Jakobsen · 2025

This chapter examines Security Information and Event Management (SIEM) systems as essential tools for centralising and analysing security data across organisational environments. It explores the core components of SIEM architecture, including log collection methods, data processing engines, log enrichment, storage solutions and analysis interfaces. The chapter provides practical implementation guidance using the ELK stack (Elasticsearch, Logstash, Kibana) and demonstrates integration with security tools such as Suricata and Velociraptor. Special attention is given to strategic approaches for log selection using the MITRE ATT&CK framework, detection tuning to reduce false positives and the standardisation of detection rules through Sigma. The chapter concludes with discussions on incident response frameworks following NIST SP 800-61, the role of Security Orchestration, Automation and Response (SOAR) platforms and considerations for Managed Security Service Providers (MSSPs).

Read the paper · More papers on PaperTik