Transcription of Magic Quadrant for Security Information and Event …
{{id}} {{{paragraph}}}
Magic Quadrant for Security Information andEvent ManagementPublished: 4 December 2017 ID: G00315428 Analyst(s): Kelly M. Kavanagh, Toby BussaSecurity and risk management leaders are implementing and expandingSIEM to improve early targeted attack detection and response. Advancedusers seek SIEM with advanced profiling, analytics and response Definition/DescriptionThe Security Information and Event management (SIEM) market is defined by the customer's needto analyze Event data in real time for the early detection of targeted attacks and data breaches, andto collect, store, analyze, investigate and report on Event data for incident response, forensics andregulatory compliance. The vendors included in our Magic Quadrant analysis have productsdesigned for this purpose, and they actively market and sell these technologies to the securitybuying tools aggregate Event data produced by Security devices, network infrastructure, systems andapplications. The primary data source is log data, but SIEM tools can also process other forms ofdata, such as NetFlow and network packets, or contextual Information about users, assets, threatsand vulnerabilities that can be found inside or outside the enterprise and that can be useful to enrichlogs and raw data.
Magic Quadrant Figure 1. Magic Quadrant for Security Information and Event Management Source: Gartner (December 2017) Vendor Strengths and Cautions
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}