Are SIEM and Log Management the Same Thing?

Log management has been around for awhile, but is SIEM taking over?

By Greg Shipley
Tue, July 01, 2008

Network World — Like many things in the IT industry, there's a lot of market positioning and buzz tossed around regarding how the original term of SIM (Security Information Management), the subsequent marketing term SEM (Security Event Management), the newer combined term of SIEM (Security Information and Even Management) relate to the long standing process of log management.

The basics of log management aren't new. Operating systems, devices and applications all generate logs of some sort that contain system-specific events and notifications. The information in logs may vary in overall usefulness, but before one can derive much value out of them, they first need to be enabled, then transported and eventually stored. It is here that the first challenge of log management is presented: how does one gather this data from an often distributed range of systems and get it into a centralized (or at least semi-centralized) location? There are varying techniques to accomplish centralization, ranging from standardizing on the syslog mechanism and then deploying centralized syslog servers, to using commercial products to address the log acquisition, transport and storage issues. Some of the other issues in log management include working around network bottlenecks, establishing reliable event transport (such as syslog over UDP isn't exactly the most robust of models), setting requirements around encryption, and managing the raw data storage issues.

So the first steps in this process are figuring out what type of log and event information you want to gather, how to transport it, and where to store it. But that leads to another major consideration: once you have it, what do you want to do with it? It is at this point where basic log management ends and the higher-level functions associated with SIEM begins.

SIEM products typically provide many of the features required for log management but add event-reduction, alerting and real-time analysis capabilities. They provide the layer of technology that allows one to say with confidence that not only are logs being gathered but they are also being reviewed. SIEM also allows for the importation of data that isn't necessarily event-driven (such as vulnerability scanning reports)—hence the "Information" portion of SIEM.

In watching the market mature over the past 10 years we believe there is room for both traditional log management tools and the real-time analysis capabilities provided by SIEM tools, but we suspect that organizations would prefer to go to a single vendor for both. Clearly organizations have to solve the first problem (log management) in order to address the second (analysis and monitoring), but the wise purchaser will know that after the first problem is addressed the second will become immediately apparent. Plan accordingly.

SIEM

Get up to speed on IT recruiting.

Learn More »
Loading...
Most Recent IT Organization Stories
In The Forrester Wave: Agile Development Management Tools report, Rally received the highest overall combined score of the 10 providers reviewed. Forrester states, "Rally in particular shows strong support for Agile project and release management... and strong reporting and analytics."
This white paper describes typical reactions to falling budgets and common problems they cause. It then recommends an alternative for achieving cost-savings and improved prioritization using a more Agile framework for effective portfolio management.
Enterprises today do not want to be pinned down to one type of architecture. Instead, they want to enjoy global application delivery via a blend of physical, virtual and cloud computing environments. With F5, IT can provide that flexibility without risking application performance and reliability. This white paper explains how.
A report on why market-leading companies use business analytics to their competitive advantage.
Forrester Research conducted in-depth interviews with users who moved from multiple automated point solutions to Application Performance Management.
Use the results of this 2010 Gartner Magic Quadrant to help with vendor selection for Application Performance Monitoring (APM) tools.
Grappling with a sprawl of printing and imaging devices across your organization? It's not uncommon today. Many IT leaders say they lack insight into how devices are being used, which ones need updating, and how to best allocate assets across their company. This challenge is causing escalating costs and is creating inefficiencies. In this webcast, we explore managed print services: what it is, how it improves workflow and why it ultimately reduces IT costs.
Join Aternity, a Gartner Cool Vendor in IT Operations, for a live demo on how Fortune 500 companies are leveraging our award-winning platform to deliver a user-centric approach to Proactive IT Management.

When: Sept. 15th / 11 AM PT / 2 PM ET
Watch this on-demand Webinar with Elaina Stergiades, IDC senior research analyst, to discover how IT organizations can better meet the needs of their internal customers.
This webcast, featuring Jim Malone, Senior Editorial Director from IDG Solutions Group and Juan Jones, Senior Vice ...
New Age of Collaboration - Study Reveals a Balancing Act Between Culture and Technology
Strategic planning is critical for your success, yet new research shows it often falls short in even the best organ...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center