---
title: "SIEM"
slug: "siem"
tags: ["Security log analysis"]
updated: 2023-07-07T21:59:36Z
published: 2023-07-07T21:59:36Z
canonical: "kb.expedient.com/siem"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SIEM

### Service Overview

Expedient SIEM is a powerful platform that provides the infrastructure and interface to allow clients to quickly detect and investigate security incidents so their security team can plan an effective response. Expedient maintains the hardware platform, software updates, licensing, and ongoing maintenance as a managed service so clients can focus on the security posture of their environment and not the platform monitoring it. Clients have full access to view and create dashboards, create custom alerts, and integrate operating system and application logs and events to gain full visibility into their security posture.

### Service Features

- Pay per endpoint
- Dedicated instance
- Monitor security across any cloud or platform
- Powerful out-of-the-box dashboards
- Integrated with other Expedient services
- Guided dashboard creation
- Customized retention options

### Default Deployment Settings

- Dedicated instance
- 30 days of retention
  - Longer retention is available via object storage
- Default set of dashboards

### Use Cases

- Security monitoring and alerting
- Event management
- Security log analysis
- Cloud security monitoring
- Application security monitoring
- Operating system security log analysis

### Responsibility and Accountability Matrix

| **SIEM Responsibility Matrix** |
| --- |
| **Platform** |
| **Task** | **Expedient** | **Client** | **Co-Managed** | **Co-Managed tasks can be performed by Expedient or Client based on Client's preference** |
| Procure, Install, Configure, Manage and Maintain Hardware | X |  |  |  |
| Procure, Install, Configure, Manage and Maintain Software | X |  |  |  |
| Capacity Management & Reporting | X |  |  |  |
| Management Console User and Access Management |  |  | X |  |
| **Management** |
| Install Agents - Windows |  |  | X | Expedient will assist with agent installs |
| Configure Agents - Windows |  |  | X |  |
| Install Agents - Linux |  |  | X | Expedient will assist with agent installs |
| Configure Agents - Linux |  |  | X |  |
| **Monitoring** |
| Deploy standard dashboards | X |  |  | Expedient creates default dashboards for Expedient services and operating system monitoring. Clients can create additional dashboards to meet more specific needs. |
| Create custom dashboards |  | X |  |  |
| Configure Expedient service integrations | X |  |  | Expedient will configure all integrations with Expedient services |
| Configure third party/external integrations |  | X |  |  |
| Monitoring and alerting for alarm thresholds |  |  | X | Expedient will create a set of default alarms, clients can create custom alerts and modify default alerts as necessary |
| Troubleshoot alerts |  |  | X | Expedient services are limited to tasks with the operating system, monitoring agent, and Expedient services. Clients are responsible for application-level troubleshooting |

### Supported Platforms

| #### Applications/Platforms Supported |
| --- |
| **Expedient Services** - Expedient Enterprise Cloud - Expedient Dedicated Private Cloud - Expedient vColo - Cloud Data Protection - Push Button DR - Endpoint Security - Micro Segmentation - Identity Management - Multi-Cloud Firewall - Juniper vSRX - Secure User VPN |
| ##### Guest Operating Systems - Windows Server 2016 to 2022 - Windows Server 2012 will be end of support in 2023 - Linux: RHEL/CentOS 6.6+ \| Ubuntu 18.04+ |
| ##### Physical Servers - Windows Server 2016 to 2022 - Windows Server 2012 will be end of support in 2023 - Linux: RHEL/CentOS 6.6+ \| Ubuntu 18.04+ |
| **Hyperscale Cloud** - Amazon Web Services - Microsoft Azure - Google Cloud Platform |
| **On-Premises Workloads** - Windows Server 2016 to 2022 - Windows Server 2012 will be end of support in 2023 - Linux: RHEL/CentOS 6.6+ \| Ubuntu 18.04+ |

### Unsupported Platforms

| #### Applications/Platforms Not Supported |
| --- |
| **Operating Systems** - Windows - Pre-Server 2012 - Desktop versions of Windows - Linux - SUSE - CentOS Stream |
