Security Information and Event Management (SIEM) Flashcards
What is a SIEM?
Security Information Event Management
solution that provides real-time or near real-time analysis of your security alerts that are being generated by network hardware and applications.
What is an Agent?
small piece of software that’s going to be installed on each system, such as a server or workstation from which the SIEM needs to gather and collect log data.
What is Agentless Installation?
Under this approach, the SIEM system will directly collect log data from each system using a standard protocol like SNMP or WMI.
What is Splunk?
market-leading big data information-gathering and analysis tool that can import machine-generated data via a connector or a visibility add-on.
What ELK (Elastic Stack)?
collection of free and open source SIEM tools that provide storage, search, and analysis functions.
What is ArcSight?
SIEM log management and analytics software that can be used for compliance reporting for legislation and regulations like HIPAA, SOX and PCI DSS
What is QRadar?
SIEM log management analytics and compliance reporting platform, but this one was created by IBM.