Market Definition/Description
This document was revised on 12 October 2022. For more information, see the Corrections page on gartner.com.
SIEM aggregates the event data that is produced by monitoring, assessment, detection and response solutions deployed across application, network, endpoint and cloud environments. Capabilities include threat detection, through correlation and user and entity behavior analytics (UEBA), and response integrations commonly managed through security orchestration, automation and response (SOAR). Security reporting and continuously updated threat content through threat intelligence platform (TIP) functionality are also common integrations. Although SIEM is primarily deployed as a cloud-based service, it may support on-premises deployment.
https://www.gartner.com/doc/reprints?id=1-2AHCXAHG&ct=220701&st=sb