Another week in the books. Another Friday SIEM post.
This week I want to throw a thought out there. Not a hot take. Not a conclusion. Just something I keep running into more and more (maybe this is a worth a full blog)
Is the SIEM slowly turning into an alert aggregator?
Or maybe better said. A place where we collect alerts from other platforms, try to fix their bad detections, and keep some logs around for when things really go wrong. Almost like a “bad detection fixer” with long term storage.
And yes, this immediately clashes with the classic advice.
Do not ingest what you do not need!
Let me back up.
Today, almost every security product ships with alerts. CSPM, CNAPP, cloud security platforms. Identity providers like Okta. Cloud providers with GuardDuty, SCC, you name it. Even Slack sends security alerts now. Salesforce too. Not even going to argue how good or bad those are.
Why is this happening. Because everyone wants to say they have security covered. Certifications. Compliance. “We will alert you if something bad happens.” Sounds good on a slide.
In reality, most of these alerts are just due diligence. Thin logic. Little context. Enough to say something happened, not enough to understand what actually happened.
Slack is a good example. I get an alert. Great. But to actually understand it, I still need to pull audit logs, correlate events, and reconstruct who did what and where. At that point I could just write the detection myself with proper correlation and full control. Otherwise I am stuck hoping the vendor does not change their rules and break my assumptions.
And of course, it is usually much easier to consume vendor alerts than to ingest their raw logs. Some tools we buy them specifically for that.
So now here we are..
Do we collect alerts from everywhere and then pull just enough logs to add context.
Or do we ingest everything, build detections the way we want, and keep all the data around for deep investigations when things really go sideways.
Probably there is not right answer as it depends every org has its reasons.
But the direction feels obvious. As more tools ship alerts by default, the role of the SIEM is changing whether we like it or not.
The SIEM is not becoming only an alert aggregator. It is becoming a decision orchestration layer. Alerts are inputs. Logs are optional context. Detections are no longer always authored in the SIEM, but decisions still happen there.
Curious how others are thinking about this.
Are you leaning toward alert aggregation with selective context, or full data ingestion and owning detections end to end?
Originally posted on LinkedIn on 12 December 2025.
Read the original post and the comments.


