Friday SIEM Post: Where do you enrich? SIEM, SOAR, or everywhere?
This keeps coming up and there's no single right answer. But there are patterns that work better than others.
SIEM-level enrichment is getting more popular. Makes sense. If you have context at detection time, your correlation rules actually mean something. A service account login hits different when you already know from CMDB that system was decommissioned last month.
The tradeoff is obvious . More data in the SIEM means more cost, more pipelines to maintain.
How I see ir:
Internal context (CMDB, IAM, asset criticality) belongs in the SIEM. This is foundational. Without it your detections are guessing about what matters.
Threat intel enrichment makes more sense at the SOAR/AI SOC layer. No need to run TI lookups on every log at ingest. Do it when an alert fires and you need to make a decision.
This also ties into whether you're doing additional dedup and correlation at the SOAR/AI SOC level. If you are, that's another enrichment opportunity. If you're not, your analysts are probably swimming in duplicate alerts.
I've always done both. SIEM enrichment improves detection quality. SOAR/AI SOC enrichment improves response quality.
Trying to do everything in one layer usually means you do none of it well.
What are you all running? Single layer or both?
Originally posted on LinkedIn on 27 February 2026.
Read the original post and the comments.


