SIEM in cyber security is a logging tax, not a detection strategy
At my last fintech, every endpoint, identity provider, and cloud account fed the SIEM. An attacker still moved laterally for two days without triggering a rule. The logs were present; the detection engineering was not.