Infrastructure monitoring tools capture the health and resource utilization of IT infrastructure components wherever they reside (e.g., in a data center, at the edge, or IaaS or PaaS in the cloud). This enables I&O teams to monitor the availability and resource utilization data of physical, virtual, software entities, and AI systems — including servers, containers, network devices, database instances, hypervisors, storage, and basic application monitoring. These tools collect data in near real time and perform historical data analysis or trending of the elements they monitor.
Security information and event management (SIEM) is a configurable system of record that collects, aggregates and analyzes security event data from on-premises and cloud environments. SIEM processes security event data for the purposes of threat detection, investigation and response. It natively supports data normalization and offers user-configurable detection content and reporting to orchestrate threat mitigation and satisfy compliance requirements. These solutions are delivered via a SaaS platform or client-hosted on-premises or private cloud. The security information and event management (SIEM) system must assist with: 1. Aggregating and normalizing data from various IT and operational technology (OT) environments. 2. Designing and executing near real-time monitoring and alerting content. 3. Enriching and investigating security events of interest. 4. Supporting manual and automated response actions. 5. Maintaining and reporting on current and historical event data.