SIEM Security Information and Event Management
Central system that collects logs from everything and looks for security incidents.
Servers, firewalls, IDS, endpoints — all ship logs to SIEM, which correlates patterns. Classics: Splunk, IBM QRadar. Modern: Wazuh (open source), Elastic Security. The foundation of a SOC.