Security

SIEM

Also written as Security Information and Event Management, Splunk

A system that collects and analyzes security-related logs and events from across an organization's systems, to detect and alert on suspicious activity.

Think of it like

Like a building's central security office that pulls in every camera feed and alarm sensor into one dashboard, instead of a guard checking each door separately.

Junior or senior?

Junior sounds like

Has only responded to alerts a SIEM already had configured.

Senior sounds like

Has written or tuned a detection rule themselves and can describe what it was looking for.

Ask them

“Have you written or tuned a detection rule in a SIEM yourself? What was it looking for?”