Microsoft Sentinel is an example of a SIEM tool. It is a cloud-native security information and event management platform that collects security data, detects threats, generates alerts, supports investigations and helps security teams respond to incidents.
A SIEM tool can monitor security activity across cloud services, applications, endpoints, servers, networks and on-premises infrastructure. Other well-known examples include:
| SIEM Tool | Best Known For |
|---|---|
| Microsoft Sentinel | Cloud-based monitoring across Microsoft, multicloud and on-premises environments |
| Splunk Enterprise Security | Security analytics, threat detection, investigation and incident response |
| IBM QRadar SIEM | Centralised security monitoring and event correlation |
How Does Microsoft Sentinel Work as a SIEM?
Microsoft Sentinel collects security information from sources such as:
- User identities and accounts
- Endpoints and servers
- Cloud services
- Applications
- Network devices
- Security products
- On-premises infrastructure
Microsoft Sentinel analyses and correlates this data to identify suspicious activity. Security teams can use it to monitor events, investigate incidents, hunt for threats and automate selected response actions.
Example Use Case
An attacker might repeatedly attempt to sign in to a user account from unusual locations. Microsoft Sentinel can correlate the authentication logs, identify the suspicious pattern and create an incident for investigation.
Is Splunk Enterprise Security Also a SIEM Tool?
Yes. Splunk Enterprise Security is another example of a SIEM tool. Splunk describes it as a security information and event management solution that collects, searches and correlates data to detect and investigate threats. Its capabilities also include security orchestration and automation, threat intelligence and user and entity behaviour analytics.
What Does a SIEM Tool Do?
A SIEM tool generally helps an organisation:
- Collect security logs and event data.
- Correlate activity from multiple systems.
- Detect potential cyberthreats.
- Generate alerts and incidents.
- Support security investigations.
- Automate selected response actions.
- Maintain searchable records for monitoring and compliance.
Microsoft Sentinel is one example. Splunk Enterprise Security and IBM QRadar SIEM are two others.