Centralized event and log data collection
Effectiveness of real-time centralized event and log data collection
Cat avg: 9
Effectiveness of real-time centralized event and log data collection
Cat avg: 9
Ability to detect both endpoint intrusion and network ingress detection
Cat avg: 7.4
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Cat avg: 8.5
Ease and quality of data integrations between SIEM and other systems
Cat avg: 8.1
dashboards that can be customized to meet the needs of specific groups
Cat avg: 8
How effectively activity and behavior baselines are established and maintained
Cat avg: 7.5
Quality of built-in response orchestration and automation in Next-Gen SIEM
Cat avg: 7.1
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
Effectiveness of real-time centralized event and log data collection
Category average: 9
Correlation of logs and events to pinpoint significant threats
Category average: 8.4
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Category average: 8.5
Ability to tune system to maximize threat detection and minimize false positives
Category average: 7.7
Integration with access control tools like Active Directory and LDAP
Category average: 7.7
dashboards that can be customized to meet the needs of specific groups
Category average: 8
Ability to detect both endpoint intrusion and network ingress detection
Category average: 7.4
Ease and quality of data integrations between SIEM and other systems
Category average: 8.1
How effectively activity and behavior baselines are established and maintained
Category average: 7.5
Effectiveness of manually-established rules and algorithmically-determined detection thresholds
Category average: 8.2
Quality of built-in response orchestration and automation in Next-Gen SIEM
Category average: 7.1
Ease and quality of reporting and compliance functions
Category average: 8.3
Effectiveness of searching across structured and unstructured events and incidents within SIEM
Category average: 8.8
Correlation of logs and events to pinpoint significant threats
Integration with access control tools like Active Directory and LDAP
dashboards that can be customized to meet the needs of specific groups
How effectively activity and behavior baselines are established and maintained
Effectiveness of manually-established rules and algorithmically-determined detection thresholds
Ease and quality of reporting and compliance functions