flâneur — a map of the web's best reading

Survivor's Guide to SIEM in 2024 - by Omer Singer

omeronsecurity.com · saved by 1 readers

This isn’t another post about the morning of May 15, when IBM Qradar customers learned that the company was exiting the SIEM business. They could start from scratch with Palo Alto Networks’ XSIAM product or something else entirely. You don’t have to go home, but you can’t stay here. Industry pundits have been discussing the news ad nauseam, so I won’t rehash why these products hit a wall and whether those were savvy business deals. Instead, I present how an ownership mindset can prepare your organization for what comes next. So far, the biggest progress towards breaking lock-in and taking ownership has been around data pipelines. In the past, data collection tooling was seen as an integral part of SIEM. Splunk has Universal Forwarders, Securonix has Remote Ingestion Nodes, etc. Typical enterprise deployments include thousands of agents installed on servers and networks throughout the organization. The many-to-one approach became less popular as demand grew for multiple pipeline destina

This isn’t another post about the morning of May 15, when IBM Qradar customers learned that the company was exiting the SIEM business. They could start from scratch with Palo Alto Networks’ XSIAM product or something else entirely. You don’t have to go home, but you can’t stay here. Industry pundits have been discussing the news ad nauseam, so I won’t rehash why these products hit a wall and whether those were savvy business deals. Instead, I present how an ownership mindset can prepare your organization for what comes next. So far, the biggest progress towards breaking lock-in and taking owne

Explore this link on the map →