P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Security and edge

Log collector (SIEM): what it is and how it is attacked

Collects the records of what happened, from every computer and system, into one place.

Also known as

  • SIEM
  • log server
  • syslog

Typing any of them into the editor finds this object.

Why it matters on a security diagram

If it is not collecting from a system, an incident on that system leaves no trace to investigate.

How it gets attacked, and what reduces it

How it gets attacked

  • Logs cleared or forwarding stopped to remove the trail
  • Retention too short to cover how long the intruder was present

What reduces it

  • Check what is not sending to it, which is the question that matters
  • Retain for longer than the time an intruder is typically present, or the records will not cover the incident
  • Write records somewhere the systems they describe cannot delete

Where it sits

Group
Security and edge · The things that sit in front of something else and check what is trying to reach it.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
log-collector

Reviewed . CC BY 4.0.

Others in security and edge

The security and edge group lists all 11 of them side by side.

Log collector on your own diagram

Open the editor, press N, and type SIEM. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker