Drowning in alerts
A SIEM is meant to be the security command centre: collecting, analysing and responding to events across firewalls, WAFs, intrusion systems, cloud platforms and endpoints. Most estates have one. Few get decisions out of it. The symptoms are the same everywhere: thousands of daily alerts, most of them noise; logs in silos that cannot be correlated; events without context, so routine activity and genuine threats look alike; and analysts sifting logs by hand while the clock runs.
SIEM is no longer about collecting logs and generating alerts. Its job is to decide.
SIEM done right, in one view
A SIEM earns its keep by deciding: which event matters, how much, and what happens next. Five mistakes stop it deciding at all.
| # | The mistake | Do it right |
|---|---|---|
| 01 | No clear objectives; SIEM as a one-size-fits-all purchase | Define the use cases first: insider threats, compliance, cloud risk, response time |
| 02 | Too much data, or too little | Prioritise firewall, endpoint, cloud and identity logs; filter and normalise; review sources regularly |
| 03 | Default configuration for a non-default estate | Customise correlation rules, add behavioural baselines, refine thresholds until alerts are believable |
| 04 | No automation | Playbooks for the repetitive: containment, suspicious logins, phishing; integrate endpoint, cloud and network tools |
| 05 | Deploy and forget | Fresh threat intelligence, rules tuned from real incidents, health checks, response drills |
What a SIEM should decide
Is this one event, or one attack?Correlation across sources. A login from an unusual location followed by an unauthorised file transfer is not two alerts; it is one compromised account.
How much does it matter?Risk-based prioritisation, with machine learning separating false positives from real threats instead of leaving the analyst to.
Is this normal for this user or system?Behavioural baselines. An employee reaching sensitive files outside working hours is a deviation worth a look; the same access at 10am is not.
What happens now?Automated response through SOAR: isolate the infected host, revoke the token, open the ticket, notify the team.
Have we seen this before?Threat intelligence in the loop, so a known malicious address is blocked on sight.
Can we show the auditor?Compliance evidence, with logs collected, events documented and reports produced automatically.
Five deployment mistakes
The exhibit lists them. Two deserve emphasis. Ingesting everything feels safe and produces a system nobody can afford to query; ingesting only what is convenient produces blind spots exactly where attackers operate. And a SIEM left on its default configuration will fit a default estate, which nobody has.
A SIEM without objectives is a very expensive log store.
SIEM plus SOAR
Orchestration and automation turn detection into response. When the SIEM flags a threat, playbooks execute: compromised endpoints are isolated, access is revoked, forensic collection starts. Alert triage is automated, so analysts spend their time on the incidents that need judgement. Tools that never talked to each other, firewalls, endpoint protection, threat intelligence, act together. Evidence for compliance is produced as a by-product of response rather than assembled before the audit. And the operation scales: more incidents handled with the same people.
Where the next generation is heading
Traditional SIEM focused on log collection, correlation and rule-based alerts, and paid for it in alert fatigue, operating cost and slow response. The platforms replacing it add artificial intelligence that finds unknown patterns and learns from every event; automation that cuts time to detect and time to respond; extended detection that unifies endpoint, network, cloud and email; cloud-native architectures that watch APIs, containers and serverless workloads; and proactive intelligence, from behavioural analytics to threat hunting for indicators of compromise before they become incidents.
Where to begin
Write down the five things your SIEM must detect for your business, not for the vendor's demo. Check whether the log sources that would reveal each one are actually flowing. Tune one correlation rule until its alerts are believable, then the next. Automate the response your analysts perform most often. And run a drill: simulate the attack, watch the SIEM, fix what it missed.
The heartbeat of cyber security has not skipped a beat. It is only getting stronger.
This perspective expands an article and a post first published by the author on LinkedIn.
