A SIEM is the best best security product you can have for when (not if) your have a security event on your network. Defensive solutions are important, but they will eventually fail to prevent a breach. When that happens, you need an early warning system - a SIEM. Feel free to reach out to me to discuss further: smurphy(at)myarg(dot)com. All the best! Steve