Event and anomaly collection. An essential component of
the architecture is concerned with collection of data from a
variety of sources, such as intrusion detection systems (IDS),
network sensors, security and service logs, etc. As large
amounts of data are available in an organization, this
component will address issues such as effective and efficient
data indexing, storage, querying and classification.