We must also avoid making excessive promises.
A SIEM does not guarantee that an attack will be detected.
Its capacity depends in particular on:
- the quality of the logs
- their availability
- rules
- configuration
- techniques used by the attacker
- of the available visibility
- analysts' skills
- of the context.
A SIEM should therefore be considered as a detection and visibility capability, and not as an absolute guarantee of security.