The SIEM can also help audit teams answer certain questions:
- Who has accessed this resource?
- When ?
- From which machine?
- Which administrator made this change?
- When did this configuration change?
- Who created this account?
- Who deleted this user?
- What activity took place before the incident?
The ability to retrieve this information can be crucial.