If your only tool is a hammer, you see every problem as a nail. It’s the same with security information and event management (SIEM). If your strategy is to use the SIEM to "log everything just in case", you have set yourself up for a classic (and expensive) dilemma.