Event and log normalization/management
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Cat avg: 8.5
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Cat avg: 8.5
Effectiveness of real-time centralized event and log data collection
Cat avg: 9
Correlation of logs and events to pinpoint significant threats
Cat avg: 8.4
dashboards that can be customized to meet the needs of specific groups
Cat avg: 8
Effectiveness of searching across structured and unstructured events and incidents within SIEM
Cat avg: 8.8
Quality of built-in response orchestration and automation in Next-Gen SIEM
Cat avg: 7.1
Ease and quality of data integrations between SIEM and other systems
Cat avg: 8.1
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
Effectiveness of real-time centralized event and log data collection
Category average: 9
Correlation of logs and events to pinpoint significant threats
Category average: 8.4
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Category average: 8.5
Ability to tune system to maximize threat detection and minimize false positives
Category average: 7.7
Integration with access control tools like Active Directory and LDAP
Category average: 7.7
dashboards that can be customized to meet the needs of specific groups
Category average: 8
Ability to detect both endpoint intrusion and network ingress detection
Category average: 7.4
Ease and quality of data integrations between SIEM and other systems
Category average: 8.1
Effectiveness of manually-established rules and algorithmically-determined detection thresholds
Category average: 8.2
Quality of built-in response orchestration and automation in Next-Gen SIEM
Category average: 7.1
Ease and quality of reporting and compliance functions
Category average: 8.3
Effectiveness of searching across structured and unstructured events and incidents within SIEM
Category average: 8.8
Effectiveness of real-time centralized event and log data collection
Correlation of logs and events to pinpoint significant threats
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Ability to tune system to maximize threat detection and minimize false positives
Integration with access control tools like Active Directory and LDAP
dashboards that can be customized to meet the needs of specific groups
Ability to detect both endpoint intrusion and network ingress detection
Length and quality of log storage and archiving over time
Ease and quality of data integrations between SIEM and other systems
How effectively activity and behavior baselines are established and maintained
Effectiveness of manually-established rules and algorithmically-determined detection thresholds
Quality of built-in response orchestration and automation in Next-Gen SIEM
Ease and quality of reporting and compliance functions
Effectiveness of searching across structured and unstructured events and incidents within SIEM