The Security Data Fabric Identity Crisis - by Omer Singer
Big changes are happening to how security teams get their data. For years, data collection was a function of the SIEM. Splunk’s app store, for example, includes hundreds of supported connectors that integrate with everything from firewalls to vulnerability scanners. In parallel, large SOCs formed teams to manage open-source pipelines for shaping and routing data using technologies like Apache Kafka and NiFi. Security organizations have now reached a tipping point for their data. On one side are the three V’s of data explosion: volume, velocity, and variety. Security teams are dealing with an avalanche of logs from endpoint agents, multi-cloud hybrid infrastructure, distributed workforces, and SaaS applications. Information must be collected from within the environment and from outside via APIs. It’s also more valuable than ever, with advances in AI enabling new insights on risks and threats. Add “value” as a fourth V driving the need for data pipeline investment. Subscribed On the othe
Big changes are happening to how security teams get their data. For years, data collection was a function of the SIEM. Splunk’s app store, for example, includes hundreds of supported connectors that integrate with everything from firewalls to vulnerability scanners. In parallel, large SOCs formed teams to manage open-source pipelines for shaping and routing data using technologies like Apache Kafka and NiFi. Security organizations have now reached a tipping point for their data. On one side are the three V’s of data explosion: volume, velocity, and variety. Security teams are dealing with an a
Explore this link on the map →