{"id":642,"date":"2026-08-13T05:59:45","date_gmt":"2026-08-13T05:59:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=642"},"modified":"2026-08-13T05:59:45","modified_gmt":"2026-08-13T05:59:45","slug":"siem","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/siem\/","title":{"rendered":"SIEM Explained: From Raw Logs to Real Alerts"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SIEM\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A SIEM collects security events from across your systems, correlates them, and raises an alert when the combination looks like an attack rather than normal activity.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Detection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>SIEM stands for security information and event management. It gathers logs from endpoints, applications, cloud accounts and identity systems, normalises them into a common format, applies correlation rules, and alerts when a pattern matches known attacker behaviour. It is also where the evidence auditors ask for is retained.<\/p>\n<\/div>\n\n<p>A single log line rarely means anything. A failed login is noise. A failed login from a new country, followed by a successful one, followed by a permission change, is an incident. Correlation is the part that turns the first into the second.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#pipeline\">How a SIEM works<\/a><\/li>\n    <li><a href=\"#sources\">What it ingests<\/a><\/li>\n    <li><a href=\"#correlation\">Why correlation matters<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs SIEM<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"pipeline\">How a SIEM works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 165\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SIEM pipeline: collect, normalise, correlate, alert, investigate.\">\n  <defs><marker id=\"siA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n  <rect x=\"8\" y=\"34\" width=\"134\" height=\"82\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"75\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">1. Collect<\/text>\n  <text x=\"75\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Logs from every<\/text>\n  <text x=\"75\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">system in scope<\/text>\n  <line x1=\"148\" y1=\"75\" x2=\"162\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#siA)\"\/>\n\n  <rect x=\"168\" y=\"34\" width=\"134\" height=\"82\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"235\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">2. Normalise<\/text>\n  <text x=\"235\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">One format, one<\/text>\n  <text x=\"235\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">timeline<\/text>\n  <line x1=\"308\" y1=\"75\" x2=\"322\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#siA)\"\/>\n\n  <rect x=\"328\" y=\"34\" width=\"134\" height=\"82\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"395\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#25547a\">3. Correlate<\/text>\n  <text x=\"395\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Link events across<\/text>\n  <text x=\"395\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">systems<\/text>\n  <line x1=\"468\" y1=\"75\" x2=\"482\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#siA)\"\/>\n\n  <rect x=\"488\" y=\"34\" width=\"134\" height=\"82\" rx=\"14\" fill=\"#7b9dc9\"\/>\n  <text x=\"555\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">4. Alert<\/text>\n  <text x=\"555\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#eaf1f8\">Raise only what<\/text>\n  <text x=\"555\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#eaf1f8\">needs a human<\/text>\n  <line x1=\"628\" y1=\"75\" x2=\"642\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#siA)\"\/>\n\n  <rect x=\"648\" y=\"34\" width=\"104\" height=\"82\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"700\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">5. Retain<\/text>\n  <text x=\"700\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Searchable<\/text>\n  <text x=\"700\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">evidence trail<\/text>\n\n  <text x=\"380\" y=\"148\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Steps 1 and 2 are plumbing. Step 3 is where a SIEM either earns its cost or becomes an alert firehose.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"sources\" class=\"c-sage\">What it ingests<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Source<\/th><th>Events that matter<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Identity and access<\/strong><\/td><td>Sign-ins, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> challenges, privilege changes, new admin accounts<\/td><\/tr>\n    <tr><td><strong>Endpoints<\/strong><\/td><td>Malware detections, unusual process activity, device policy violations<\/td><\/tr>\n    <tr><td><strong>Cloud accounts<\/strong><\/td><td>Configuration changes, new IAM roles, storage made public, key usage<\/td><\/tr>\n    <tr><td><strong>Web and API layer<\/strong><\/td><td>Blocked attacks, unusual request patterns, credential stuffing attempts<\/td><\/tr>\n    <tr><td><strong>Applications<\/strong><\/td><td>Authentication failures, data exports, administrative actions<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"correlation\" class=\"c-apri\">Why correlation matters<\/h2>\n\n<p>Each of the events below is unremarkable alone. Together they describe an account takeover in progress, and only a system holding all of them can see that.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 260\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Three separate low-priority events from identity, endpoint and cloud combining into one high-priority correlated alert.\">\n  <defs><marker id=\"siB\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"34\" width=\"238\" height=\"52\" rx=\"10\" fill=\"#f4f5fd\"\/>\n  <text x=\"28\" y=\"56\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Identity<\/text>\n  <text x=\"28\" y=\"75\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Sign-in from an unusual location<\/text>\n  <rect x=\"12\" y=\"96\" width=\"238\" height=\"52\" rx=\"10\" fill=\"#f4f5fd\"\/>\n  <text x=\"28\" y=\"118\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Endpoint<\/text>\n  <text x=\"28\" y=\"137\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">New device registered to the account<\/text>\n  <rect x=\"12\" y=\"158\" width=\"238\" height=\"52\" rx=\"10\" fill=\"#f4f5fd\"\/>\n  <text x=\"28\" y=\"180\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Cloud<\/text>\n  <text x=\"28\" y=\"199\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Access key created minutes later<\/text>\n  <text x=\"131\" y=\"234\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Three low-priority events<\/text>\n\n  <line x1=\"258\" y1=\"122\" x2=\"322\" y2=\"122\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#siB)\"\/>\n  <text x=\"290\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">correlate<\/text>\n\n  <rect x=\"336\" y=\"76\" width=\"180\" height=\"92\" rx=\"14\" fill=\"#e2eff7\"\/>\n  <text x=\"426\" y=\"112\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#2f6a89\">Same identity<\/text>\n  <text x=\"426\" y=\"133\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Same 20-minute window<\/text>\n  <line x1=\"524\" y1=\"122\" x2=\"588\" y2=\"122\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#siB)\"\/>\n\n  <rect x=\"602\" y=\"76\" width=\"146\" height=\"92\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"675\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">One alert<\/text>\n  <text x=\"675\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Possible account<\/text>\n  <text x=\"675\" y=\"144\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">takeover<\/text>\n  <text x=\"675\" y=\"234\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">One high-priority incident<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Point tools each hold one of these events. None of them can see the sequence.<\/figcaption>\n<\/figure>\n\n<h2 id=\"frameworks\" class=\"c-plum\">Where frameworks require it<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>PCI DSS v4.0<\/strong><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Requirement 10: log all access to system components, review logs, retain 12 months.<\/td><\/tr>\n    <tr><td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>:2022<\/strong><\/td><td><span class=\"pill p-exp\">Expected<\/span><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 8.15 logging and A 8.16 monitoring activities.<\/td><\/tr>\n    <tr><td><strong>SOC 2<\/strong><\/td><td><span class=\"pill p-exp\">Expected<\/span><\/td><td>CC7.2 monitoring for anomalies, and <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">evidence that alerts are investigated<\/a>.<\/td><\/tr>\n    <tr><td><strong>DPDP Act, 2023<\/strong><\/td><td><span class=\"pill p-imp\">Implied<\/span><\/td><td>Detection and timeline evidence needed for a 72-hour breach report.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto runs SIEM<\/h2>\n\n<p>Most SIEM projects fail at collection, because logs arrive from a dozen vendors in a dozen shapes and someone has to build the pipeline. Osto avoids that step: endpoint, IAM, ZTNA, WAF, cloud posture and vulnerability data are already generated by the same platform, so correlation happens across modules by default rather than after an integration project. That is also what makes cross-domain detection possible, where an event in one module only becomes meaningful next to an event in another.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Detection that sees across the whole stack<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Endpoint, identity, WAF and cloud events correlated in one platform, with the retained evidence auditors ask for.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">No log pipeline to build &middot; Cross-module correlation &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does SIEM stand for?<\/summary>\n  <p>Security information and event management. A SIEM collects security events from across an organisation&#8217;s systems, normalises them, correlates them, raises alerts and retains the record for investigation and audit.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a SIEM and log management?<\/summary>\n  <p>Log management stores and searches logs. A SIEM adds correlation and detection logic on top, so related events across different systems are linked and alerted on. Every SIEM includes log management; the reverse is not true.<\/p>\n<\/details>\n\n<details>\n  <summary>Do small companies need a SIEM?<\/summary>\n  <p>They need the outcome rather than a large deployment: centralised logs, detection across systems, and a retained evidence trail for audit. Traditional SIEM products are heavy for small teams, which is why platforms that generate and correlate their own telemetry fit better.<\/p>\n<\/details>\n\n<details>\n  <summary>How long should logs be retained?<\/summary>\n  <p>It depends on the framework. PCI DSS requires twelve months with three months immediately available. SOC 2 and ISO 27001 do not fix a period, so retention follows your own documented policy, and twelve months is the common choice.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> Incident Response &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; IAM &middot; Endpoint Security &middot; Log Management &middot; Threat Detection<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A SIEM collects security events from across your systems, correlates them, and raises an alert when the combination looks like\u2026<\/p>\n","protected":false},"author":8,"featured_media":643,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[229,228],"class_list":["post-642","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-security-information-and-event-management","tag-siem"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/642","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=642"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/642\/revisions"}],"predecessor-version":[{"id":644,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/642\/revisions\/644"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/643"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=642"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=642"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=642"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}