SIEM is not solely intended for external attackers.
It can also help to detect unusual internal behaviors.
For example :
- massive file consultation
- access to resources unrelated to functions
- unusual use of a privileged account
- massive download
- permission modification
- access outside normal hours.
However, be aware:
An anomaly is not necessarily fraud. The SIEM identifies events or behaviors to investigate; it should not be used to automatically conclude that human error occurred.