Contact us

Join the community

Scan with WeChat
Join the official community group

Try Guance

Start online with usage-based pricing and a true cloud service.

Get started

Choose a Guance edition

Code repositories

Security Information and Event Management

Security information and event management (SIEM)

Guance SIEM aggregates security logs, audit events, cloud resource changes, and business access behaviors to identify abnormal logins, configuration changes, cross-account access, malicious requests, and potential attacks in real time, helping security, operations, and SRE teams integrate security analysis, threat detection, alert response, and event tracking on a single platform.

Security Information and Incident Management (SIEM)
Book a demo

The SIEM capabilities released Guance perfectly meet our needs—whether it's compliance checks, configuration audits, or analysis and traceability of abnormal behaviors, enabling us to proactively and intelligently identify potential security risks, truly achieving both performance and security during global business expansion.

———— Li Zheng Head of the ANTA Group observable project

What problems does SIEM solve?

Proactively identify threats from security logs and incidents, and establish a closed response loop

Many security issues are not due to a lack of data, but because there are too many logs, scattered rules, and fragmented context. Guance SIEM combines log retrieval, security analysis, security detection, incident center, and alert response, enabling teams to quickly detect abnormal behaviors, assess asset impacts, and incorporate every security incident into traceable workflows.

The powerful verification engine ArbiterBase

The powerful verification engine Arbiter
Too many security logs? First, identify abnormal logins, configuration changes, and cross-account access
Guance identify abnormal behaviors from login logs, audit logs, cloud platform events, application access logs, and network logs through high-performance log analysis and structured retrieval. Security teams can quickly filter evidence around accounts, IPs, hosts, services, resources, and timelines to determine whether it is false positives, configuration changes, or potential attacks.
Too many security logs? First, identify abnormal logins, configuration changes, and cross-account access
Alerts should not just be a reminder; they must link threats, assets, and context
Alerts should not just be a reminder; they must link threats, assets, and context
SIEM analyzes security data from servers, network devices, cloud services, containers, and application systems within the same context. For risks such as abnormal logins, unauthorized access to internal data, malicious file uploads, and permission changes, teams can simultaneously view relevant assets, log evidence, trigger rules, and the scope of impact, reducing situations where only receiving alerts but not knowing how to investigate.
Security incidents require a closed loop, with unified tracking and response at the incident center
Guance Incident Center aggregates security alerts, system anomalies, operation audits, and custom events, supporting aggregation, filtering, dispatching, and tracking. Security teams can accumulate a risk from discovery, analysis, response to review, and also associate it with stability events, SLOs, and business impacts, preventing security incidents from remaining only at the notification layer.
Security incidents require a closed loop, with unified tracking and response at the incident center
Don't want to write rules from scratch? Use inspection templates to quickly cover common risk scenarios
Don't want to write rules from scratch? Use inspection templates to quickly cover common risk scenarios
- Guance built-in multiple detection templates covering risk scenarios such as host security, configuration compliance, network access, container runtime, cloud resource auditing, and API call behavior.
- Teams can quickly enable query, rule, alert, and response processes based on templates, and then expand detection logic by combining them with their own business fields.
- Continuous template iteration helps enterprises lower the threshold for SIEM construction, enabling security inspection capabilities to enter daily operations more quickly.

Frequently asked questions

What is SIEM?

SIEM is Security Information and Event Management, used to centrally collect and analyze logs, audit events, alerts, and security rules, helping teams identify abnormal behaviors, assess risk impacts, and advance responses. Guance SIEM associates security incidents with hosts, cloud resources, application logs, and alert contexts.

What security risks can SIEM detect?

Common scenarios include abnormal logins, brute-force attacks, cross-account access, permission changes, configuration changes, malicious requests, abnormal file uploads, unauthorized access to internal data, abnormal cloud resource operations, and container runtime risks.

Guance What is the difference between SIEM and log monitoring?

Log monitoring focuses on log collection, retrieval, parsing, alerting, and troubleshooting; SIEM further integrates detection rules, security incidents, alarm responses, and audit context on top of logs to help teams move from "checking logs" to "identifying threats and closing the loop."

Which teams is SIEM suitable for?

SIEM is suitable for security operations, operations, SRE, platform engineering, and compliance teams, especially for enterprises looking to unify security logs, cloud resource audits, application access, and incident response into a single platform.

Explore more

Resources and further reading

Choose the next step from product documentation, related solutions, and technical guidance.

Related reading

Selected product practices, troubleshooting guidance, and technical solutions

A powerful log viewer to support data linkage analysis

A powerful log viewer to support data linkage analysis

Guance viewer's powerful query filtering and search functions help users quickly and accurately retrieve data and locate faults. The log viewer not only helps us collect and manage various log files, but also enables correlation analysis with multi-party data, providing users with more comprehensive and accurate data information to support efficient decision-making.

Product capabilities
Leverage Guance to build a unified enterprise-level log center

Leverage Guance to build a unified enterprise-level log center

Guance adheres to the philosophy of "unified collection, unified processing, and unified analysis," building an efficient observation data analysis platform. This article Guance how to help enterprises quickly and effectively build unified log centers through the various processes of log collection, processing, storage, and analysis.

Best practices
Pipeline helps you easily manage massive amounts of data!

Pipeline helps you easily manage massive amounts of data!

Data governance has become crucial in today's information age. As the volume of data continues to grow and diversify, organizations need to effectively manage and utilize this data to support business decisions and innovative development. Whether for data analysis or parsing, using Pipeline helps organizations automate and standardize data governance; Providing organizations with clearer and more actionable data views to strongly support data governance.

Product capabilities
Guance VS ELK: Who is the king of log monitoring?

Guance VS ELK: Who is the king of log monitoring?

This article provides a detailed analysis of Guance and ELK from multiple dimensions including data collection, data storage, data query, data visualization, and usage costs, providing a reference for users when making a choice.

Industry insights

Want to see how security information and incident management are implemented in your business systems?

Book a demo