
A SIEM (security information and event management) is a log platform: it collects records from firewalls, servers, cloud apps and security tools, correlates them into alerts and keeps them for investigations and audits. EDR (endpoint detection and response) is an agent on each computer and server that detects attacker behavior on that machine and can isolate it. MDR (managed detection and response) is neither tool; it is a service in which a provider's analysts watch your EDR, and sometimes your SIEM, around the clock and respond.
So the real question is which tools you need and who is responsible for acting on them. Most comparisons stop at features; this one also assigns the jobs: who connects sources, who tunes detections, who decides to isolate a laptop at 3 a.m. and who keeps the evidence. For the related XDR question, see XDR vs SIEM for small business.
What is the difference between SIEM, EDR and MDR?
NIST defines a SIEM tool as an application that gathers security data from information system components and presents it as actionable information through a single interface (NIST glossary, from SP 800-128). EDR goes deep on one kind of system; a SIEM goes wide across many; MDR supplies the people.
| SIEM | EDR | MDR | |
|---|---|---|---|
| What it is | A platform that collects, correlates and retains logs | An agent and console that detect and contain threats on endpoints | A service: analysts, procedures and the authority to act |
| What it covers | Any source that emits logs: firewalls, servers, Microsoft 365, identity, line-of-business apps and EDR alerts | Laptops, desktops and servers: processes, files, network connections and sign-ins on each device | The tools it is contracted to watch: usually EDR, often identity and email, sometimes a SIEM |
| Who runs it | An analyst or managed SOC who writes rules and reviews alerts | Your IT staff or a provider | The provider, under your escalation rules |
| Who it fits | Businesses that must keep and search logs, or that run many systems outside one vendor's reach | Every business with computers and servers | Businesses without a security analyst on every shift |
| Cost drivers | Data volume, retention, connectors and the people who tune it | Per device or per user license | License plus analyst labor, per endpoint, per user or quoted |
| Effort | High, because tuning is the work | Medium: deploy, tune and triage | Low for you once escalation is agreed |
What is EDR vs SIEM?
EDR sees deeply into one device and can act on it: stop a process, quarantine a file, cut the machine off the network. A SIEM sees across everything, but on its own it alerts rather than acts; response comes from EDR, XDR or automation connected to it. The two are complementary, and a SIEM usually takes the EDR's alerts as one of its feeds. The joint SIEM and SOAR guidance that CISA, the Australian Cyber Security Centre and partners published in May 2025 includes a practitioner document on the priority logs to send to a SIEM, covering endpoint detection and response tools, Windows and Linux systems, network devices and cloud environments, according to New Zealand's NCSC summary of the series.
What is MDR vs SIEM, and where does managed SIEM fit?
MDR is measured by response: how quickly a person acts on an alert, and what they are allowed to do. A SIEM is measured by visibility and evidence: which sources are connected and how long their records are kept. A managed SIEM sits between the two: a provider runs the log platform and reviews its alerts, which may or may not include containment. Huntress, for example, publishes a Managed SIEM price of $4.00 per data source per month (MSRP, as of October 2026) next to its Managed EDR on its pricing page, an example of the two being priced separately: per data source for logs, per endpoint for EDR.
An MSSP, a managed security service provider, is the company rather than the tool: it runs agreed security functions such as monitoring, detection and response, identity and email controls, and reporting. An MSSP may deliver MDR, a managed SIEM or both, so ask which jobs are in the contract, not which acronym is on the proposal.
Who is responsible for what?
The same incident needs the same jobs done, whichever tools you buy. Typical splits:
| Job | EDR only | EDR plus MDR | SIEM plus managed SOC |
|---|---|---|---|
| Keep the agent on every device | You | Shared: the provider reports gaps, you or your IT provider fix them | Not covered; a SIEM only sees devices that send it logs |
| Read alerts at night and on weekends | You | The provider | The provider, for connected sources |
| Isolate a device or disable an account | You | The provider, within pre-approved actions | The provider if the contract grants that authority; otherwise a call to you |
| Connect firewall, server and cloud logs | Nobody | Only if the contract includes log sources | The provider, for the agreed sources |
| Keep records for audits | Whatever the EDR plan keeps, such as 14 days on SentinelOne Complete or six months on Defender for Endpoint Plan 2 | The same | The provider, for the agreed retention period |
| Recover systems and data | You | You, unless incident response is in the contract | You, unless incident response is in the contract |
Which fits a small team?
Illustrative situations, not client stories:
- Twenty-five people on Microsoft 365 Business Premium, no IT staff. EDR you already own in Defender for Business, plus MDR. A SIEM can wait until someone asks for logs.
- A regulated firm whose auditor asks for a year of searchable logs. EDR plus MDR for response, and a SIEM run by a managed SOC with retention sized to the rule.
- Several sites with their own firewalls and an on-premises ERP server. A SIEM is the only place those logs meet the endpoint and identity alerts; add it beside EDR, not instead of it.
- An insurance renewal asking about 24/7 monitoring. MDR answers that question; a SIEM that nobody watches does not.
- An internal IT team that wants to keep endpoint response. Keep EDR in-house and contract after-hours MDR, with the handoff written down.
What drives the cost?
- EDR is priced per device or user. Microsoft lists Defender for Business at $3.00 per user per month on its own, paid yearly, and includes it in Business Premium; CrowdStrike's Falcon Enterprise, its first bundle with EDR, is $184.99 per device per year (as of October 2026).
- A SIEM is priced by data or by source. Microsoft Sentinel charges per GB with the first 90 days of retention included, according to its billing guide, and its East US pay-as-you-go list price is $4.30 per GB; managed options such as Huntress's price per data source.
- MDR is priced per endpoint or user and often quoted; Huntress lists its Managed EDR, SOC included, at an MSRP of $8.99 per endpoint per month.
- Implementation and support are the hidden lines: connecting and testing sources, tuning out false alarms, and agreeing who may act without a phone call.
How does NetSys help?
We split the jobs the same way. Our managed detection and response service keeps EDR on every device, triages every alert around the clock, isolates compromised machines and writes up the root cause. Our SOC monitoring service adds the log side when a regulator, auditor or insurer needs it: the agreed sources, retention, coverage hours, severity definitions and the containment actions we may take without asking. Monitoring, containment, incident response and recovery are related but separate commitments, and our proposals say which ones are included.
Book a call with a NetSys engineer to sort out which of these jobs you already cover and which nobody owns.
Frequently asked questions
What is EDR vs SIEM?
EDR is an agent on each endpoint that detects attacker behavior and can isolate the device. A SIEM is a central log platform that collects records from many systems, including EDR, correlates them and keeps them for investigations and audits. EDR acts on devices; a SIEM gives visibility and evidence across everything.
What is the difference between MDR and SIEM?
MDR is a service: people who watch your security tools around the clock and respond. A SIEM is a tool: the platform that collects and correlates logs. An MDR provider may use a SIEM, and a SIEM needs people, in-house or managed, to be useful.
Is managed SIEM the same as MDR?
No. Managed SIEM means a provider runs the log platform and reviews its alerts; MDR means a provider detects and responds, usually starting from EDR. Some providers offer both. Ask whether containment, such as isolating a device or disabling an account, is in the contract.
Do I need a SIEM if I have MDR?
Not always. MDR on EDR is the layer that stops an attack in progress on your computers and servers. A SIEM becomes necessary when a regulation or insurer requires centralized, retained logs, or when important systems sit outside what the EDR can see.
What affects cost, implementation and support?
For EDR, the device count and tier; for a SIEM, data volume, retention and connectors; for MDR, the coverage hours and response authority. Implementation means connecting and testing every source and agent. Support depends on how clearly the escalation list and the pre-approved actions are written.
Related reading
SecurityXDR vs SIEM for Small Business: Which Do You Need?
Read Article
CybersecurityEDR vs. Antivirus vs. MDR: What Small Businesses Need
Read Article
ComparisonEDR vs XDR vs MDR: Which Protection Does a Small Business Need?
Read ArticleAlso on this topic: SOC vs NOC vs SIEM: What Each One Does for Your Business
Discuss managed detection & response (mdr) for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
