Guide24 August 20264 min read830 words

SIEM vs Law 5651 Logging: Differences and Using Them Together

SIEM is for security analytics while Law 5651 logging is for signed, evidence-grade retention; SignLogger is not a SIEM but works alongside one.

#what is siem#siem vs 5651#law 5651 logging#compliance logging

SIEM and Law 5651 compliance logging are not the same thing and do not replace each other. A SIEM is a security analytics tool that collects and correlates security events in real time; Law 5651 logging exists to preserve the integrity of access records so they hold up as legal evidence. SignLogger is not a SIEM; it focuses on signed log retention and Law 5651 compliance, and it works alongside a SIEM without conflict.

This content is for general information only and is not a substitute for legal advice. For the scope of your obligations, rely on the applicable legislation and a qualified advisor.

Purpose Gap: Analytics or Evidence?

The two approaches answer different questions. A SIEM asks, "Is something suspicious happening on my network right now?" Law 5651 logging asks, "At a given moment, which user accessed which resource, and can we prove the record was not altered afterward?" The first is a security operations concern; the second is a legal compliance concern.

  • SIEM: Aggregates events from many sources, correlates them, raises alerts, and enables threat hunting.
  • Law 5651 logging: Collects internet access and traffic records, seals their integrity with a timestamp and e-signature, and retains them for the period the legislation requires.
  • Common ground: Both collect logs, but their collection purpose, retention method, and evidential value diverge fundamentally.

Why SignLogger Is Not a SIEM

SignLogger's priority is not log analytics or threat correlation but Law 5651 compliant signed retention. The access records it gathers are sealed every day with a timestamp and e-signature from TÜBİTAK Kamu SM, an authorized certificate authority, so it can be independently proven that a record existed on a specific date and was not altered afterward. The Kamu SM service works on a credit (kontör) basis. For details, see our Law 5651 log signing solution.

SignLogger is brand-independent; it works with any RADIUS-capable firewall and is deployed on the organization's own infrastructure (VMware/Hyper-V). This keeps access data on-premises and never sends it off-site. In hotspot and captive portal scenarios, RADIUS authentication is performed with PAP.

SIEM vs Law 5651 Logging Comparison

CriterionSIEMLaw 5651 Logging (SignLogger)
Primary purposeSecurity analytics and threat detectionLegal compliance and evidence-grade retention
Signature capabilityCorrelation, alerting, threat huntingIntegrity seal via timestamped e-signature
Record integrityTypically unsigned collectionDaily Kamu SM e-signature + timestamp
Time horizonReal time and recent pastLong retention period set by legislation
DeploymentOn-prem or cloudOrganization's own infrastructure, on-prem
Use of outputSOC operations, incident responseAudits and responses to official requests

Using the Two Together

SIEM and Law 5651 logging are complementary, not competing. In the right architecture they run side by side: SignLogger keeps the access records the law requires in a signed, tamper-evident form, while the SIEM draws on the same sources to handle security correlation and alerting.

  • SignLogger holds the "official copy" of the sealed record that carries evidential value.
  • The SIEM delivers operational visibility and real-time threat detection.
  • The same log sources (firewall, authentication, DHCP) can be streamed to both systems in parallel.
  • A security incident is thus detected in the SIEM, while its legal counterpart is proven by the signed record in SignLogger.

This distinction becomes even clearer in hotspot and guest network scenarios; our hotspot management solution produces access records correctly, and SignLogger seals those records for compliance.

Frequently Asked Questions

If I already have a SIEM, do I still need Law 5651 logging?

Most likely yes. A SIEM provides security analytics but usually keeps records unsigned; what matters for Law 5651 is the timestamped e-signature that proves record integrity. Without that integrity seal, SIEM output alone may not satisfy the compliance obligation.

Does SignLogger replace a SIEM?

No. SignLogger does not perform correlation, alerting, or threat hunting; it focuses on signed log retention and Law 5651 compliance. When a SIEM is needed for security operations, SignLogger runs alongside it rather than in its place.

Can I send the same logs to both the SIEM and SignLogger?

Yes. Records from sources such as the firewall, authentication, and DHCP can be forwarded to both systems in parallel. The SIEM then handles analytics while SignLogger handles compliant, sealed retention.

How does SignLogger sign logs?

SignLogger seals the records it collects every day with a TÜBİTAK Kamu SM timestamp and e-signature. This proves that a record existed on a specific date and was not altered afterward. Because the Kamu SM service works on a credit (kontör) basis, keeping sufficient credits available is recommended.

Does the data leave the organization?

No. SignLogger runs on the organization's own infrastructure (VMware/Hyper-V) and access data stays on-premises. Only the timestamp/e-signature steps of the signing process are carried out with the authorized certificate provider.

Which firewalls does SignLogger work with?

SignLogger is brand-independent and works with any RADIUS-capable firewall or network device. This lets you add Law 5651 compliant signed retention without replacing your existing infrastructure.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo