SIEM
Also known as Security information and event management
A system that collects logs from across your environment, correlates them, and raises alerts on suspicious patterns.
A SIEM is where the audit trail lives. Firewall logs, sign-in events, endpoint telemetry, and application logs land in one place so an investigator can reconstruct what happened, and so rules can fire when a sequence looks like an attack.
They are frequently bought and rarely tuned. Without ongoing rule maintenance and someone triaging output, a SIEM becomes an expensive log archive that satisfies an auditor and detects nothing.
Where this comes up
SIEM sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.