SIEM (Security Information & Event Management) collects logs from endpoints, network gear, cloud, identity. Sentinel (Azure), Splunk, Elastic.
Detections are rules or analytics that fire on suspicious patterns. Tune relentlessly — noisy SIEMs get ignored, ignored SIEMs miss attacks.
Pair SIEM with SOAR (orchestration) and EDR (Endpoint Detection and Response) to triage and contain quickly.
