HomeBlogComparison

SIEM vs EDR vs MDR: Technology and Service Responsibilities

Pixel-art illustration of a robot on a pirate ship's deck raising a glowing blue shield against red, bug-shaped malware over a stormy sea

A SIEM (security information and event management) is a log platform: it collects records from firewalls, servers, cloud apps and security tools, correlates them into alerts and keeps them for investigations and audits. EDR (endpoint detection and response) is an agent on each computer and server that detects attacker behavior on that machine and can isolate it. MDR (managed detection and response) is neither tool; it is a service in which a provider's analysts watch your EDR, and sometimes your SIEM, around the clock and respond.

So the real question is which tools you need and who is responsible for acting on them. Most comparisons stop at features; this one also assigns the jobs: who connects sources, who tunes detections, who decides to isolate a laptop at 3 a.m. and who keeps the evidence. For the related XDR question, see XDR vs SIEM for small business.

What is the difference between SIEM, EDR and MDR?

NIST defines a SIEM tool as an application that gathers security data from information system components and presents it as actionable information through a single interface (NIST glossary, from SP 800-128). EDR goes deep on one kind of system; a SIEM goes wide across many; MDR supplies the people.

SIEMEDRMDR
What it isA platform that collects, correlates and retains logsAn agent and console that detect and contain threats on endpointsA service: analysts, procedures and the authority to act
What it coversAny source that emits logs: firewalls, servers, Microsoft 365, identity, line-of-business apps and EDR alertsLaptops, desktops and servers: processes, files, network connections and sign-ins on each deviceThe tools it is contracted to watch: usually EDR, often identity and email, sometimes a SIEM
Who runs itAn analyst or managed SOC who writes rules and reviews alertsYour IT staff or a providerThe provider, under your escalation rules
Who it fitsBusinesses that must keep and search logs, or that run many systems outside one vendor's reachEvery business with computers and serversBusinesses without a security analyst on every shift
Cost driversData volume, retention, connectors and the people who tune itPer device or per user licenseLicense plus analyst labor, per endpoint, per user or quoted
EffortHigh, because tuning is the workMedium: deploy, tune and triageLow for you once escalation is agreed

What is EDR vs SIEM?

EDR sees deeply into one device and can act on it: stop a process, quarantine a file, cut the machine off the network. A SIEM sees across everything, but on its own it alerts rather than acts; response comes from EDR, XDR or automation connected to it. The two are complementary, and a SIEM usually takes the EDR's alerts as one of its feeds. The joint SIEM and SOAR guidance that CISA, the Australian Cyber Security Centre and partners published in May 2025 includes a practitioner document on the priority logs to send to a SIEM, covering endpoint detection and response tools, Windows and Linux systems, network devices and cloud environments, according to New Zealand's NCSC summary of the series.

What is MDR vs SIEM, and where does managed SIEM fit?

MDR is measured by response: how quickly a person acts on an alert, and what they are allowed to do. A SIEM is measured by visibility and evidence: which sources are connected and how long their records are kept. A managed SIEM sits between the two: a provider runs the log platform and reviews its alerts, which may or may not include containment. Huntress, for example, publishes a Managed SIEM price of $4.00 per data source per month (MSRP, as of October 2026) next to its Managed EDR on its pricing page, an example of the two being priced separately: per data source for logs, per endpoint for EDR.

An MSSP, a managed security service provider, is the company rather than the tool: it runs agreed security functions such as monitoring, detection and response, identity and email controls, and reporting. An MSSP may deliver MDR, a managed SIEM or both, so ask which jobs are in the contract, not which acronym is on the proposal.

Who is responsible for what?

The same incident needs the same jobs done, whichever tools you buy. Typical splits:

JobEDR onlyEDR plus MDRSIEM plus managed SOC
Keep the agent on every deviceYouShared: the provider reports gaps, you or your IT provider fix themNot covered; a SIEM only sees devices that send it logs
Read alerts at night and on weekendsYouThe providerThe provider, for connected sources
Isolate a device or disable an accountYouThe provider, within pre-approved actionsThe provider if the contract grants that authority; otherwise a call to you
Connect firewall, server and cloud logsNobodyOnly if the contract includes log sourcesThe provider, for the agreed sources
Keep records for auditsWhatever the EDR plan keeps, such as 14 days on SentinelOne Complete or six months on Defender for Endpoint Plan 2The sameThe provider, for the agreed retention period
Recover systems and dataYouYou, unless incident response is in the contractYou, unless incident response is in the contract

Which fits a small team?

Illustrative situations, not client stories:

  • Twenty-five people on Microsoft 365 Business Premium, no IT staff. EDR you already own in Defender for Business, plus MDR. A SIEM can wait until someone asks for logs.
  • A regulated firm whose auditor asks for a year of searchable logs. EDR plus MDR for response, and a SIEM run by a managed SOC with retention sized to the rule.
  • Several sites with their own firewalls and an on-premises ERP server. A SIEM is the only place those logs meet the endpoint and identity alerts; add it beside EDR, not instead of it.
  • An insurance renewal asking about 24/7 monitoring. MDR answers that question; a SIEM that nobody watches does not.
  • An internal IT team that wants to keep endpoint response. Keep EDR in-house and contract after-hours MDR, with the handoff written down.

What drives the cost?

  • EDR is priced per device or user. Microsoft lists Defender for Business at $3.00 per user per month on its own, paid yearly, and includes it in Business Premium; CrowdStrike's Falcon Enterprise, its first bundle with EDR, is $184.99 per device per year (as of October 2026).
  • A SIEM is priced by data or by source. Microsoft Sentinel charges per GB with the first 90 days of retention included, according to its billing guide, and its East US pay-as-you-go list price is $4.30 per GB; managed options such as Huntress's price per data source.
  • MDR is priced per endpoint or user and often quoted; Huntress lists its Managed EDR, SOC included, at an MSRP of $8.99 per endpoint per month.
  • Implementation and support are the hidden lines: connecting and testing sources, tuning out false alarms, and agreeing who may act without a phone call.

How does NetSys help?

We split the jobs the same way. Our managed detection and response service keeps EDR on every device, triages every alert around the clock, isolates compromised machines and writes up the root cause. Our SOC monitoring service adds the log side when a regulator, auditor or insurer needs it: the agreed sources, retention, coverage hours, severity definitions and the containment actions we may take without asking. Monitoring, containment, incident response and recovery are related but separate commitments, and our proposals say which ones are included.

Book a call with a NetSys engineer to sort out which of these jobs you already cover and which nobody owns.

Frequently asked questions

What is EDR vs SIEM?

EDR is an agent on each endpoint that detects attacker behavior and can isolate the device. A SIEM is a central log platform that collects records from many systems, including EDR, correlates them and keeps them for investigations and audits. EDR acts on devices; a SIEM gives visibility and evidence across everything.

What is the difference between MDR and SIEM?

MDR is a service: people who watch your security tools around the clock and respond. A SIEM is a tool: the platform that collects and correlates logs. An MDR provider may use a SIEM, and a SIEM needs people, in-house or managed, to be useful.

Is managed SIEM the same as MDR?

No. Managed SIEM means a provider runs the log platform and reviews its alerts; MDR means a provider detects and responds, usually starting from EDR. Some providers offer both. Ask whether containment, such as isolating a device or disabling an account, is in the contract.

Do I need a SIEM if I have MDR?

Not always. MDR on EDR is the layer that stops an attack in progress on your computers and servers. A SIEM becomes necessary when a regulation or insurer requires centralized, retained logs, or when important systems sit outside what the EDR can see.

What affects cost, implementation and support?

For EDR, the device count and tier; for a SIEM, data volume, retention and connectors; for MDR, the coverage hours and response authority. Implementation means connecting and testing every source and agent. Support depends on how clearly the escalation list and the pre-approved actions are written.

Managed Detection & Response (MDR)

Discuss managed detection & response (mdr) for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Managed Detection & Response (MDR) 845-203-3914