SIEM is primarily a detection and analysis platform, but modern solutions can be integrated with response mechanisms.
For example :
An alert indicates that a workstation is likely compromised.
The system may potentially trigger a workflow that allows:
- to identify the position
- to identify the user
- to question the EDR
- to retrieve more information
- to isolate the station
- to temporarily disable an account
- to create a ticket
- to notify the security team.
This automation brings the SIEM closer to the world of:
SOAR — Security Orchestration, Automation and Response.
However, it is important to control the automation.
A faulty automated rule can lead to:
- the isolation of a critical server
- blocking a legitimate user
- the interruption of a service
- a production incident.
Automation must therefore be proportionate to the level of confidence in the detection.