One of the biggest challenges organizations face today is the need to keep more and more security data online for quick analysis by SIEM solutions. Understanding what is normal in a network is becoming increasingly important as a tool to detect breaches in the first place. A SIEM will categorize, normalize, tag and link events with paths through the network, vulnerabilities, discovered assets, users and all their properties. It will automatically utilize threat intelligence data as it performs risk and impacting scoring. It must also have to potentially be able to transfer data at millions of events per second without impacting normal operations. This means hundreds of terabytes (TBs) of data for a lot of organizations.”]
Source: https://securityintelligence.com/security-intelligence-and-siem-gets-bigger-with-ease/