The SIEM is often considered one of the central components of a:
Security Operations Center—SOC.
The SOC's mission includes, among other things:
- monitor the environment;
- detect threats;
- analyze the alerts;
- investigate the incidents;
- coordinate the response;
- improve detection capabilities.
SIEM provides a large part of the raw material needed for this activity.
The chain can be simplified as follows:
Sources → SIEM → Detection → Alert → Analysis → Investigation → Response
However, a SIEM is not a SOC.
A SIEM without processes, relevant rules, and analysts can produce a huge number of alerts without significantly improving security.