Top 10 SIEM Log Sources in Real Life? | by Anton Chuvakin | Anton on Security | Medium
One of the most common questions I received in my analyst years of covering SIEM and other security monitoring technologies was “what data sources to integrate into my SIEM first?” And of course the only honest answer to this question is: it depends on your security monitoring use cases and how you prioritize them. Naturally, some people then ask “ok, so then what are my use cases?” (and then there are these challenges too). Finally, perhaps in this paper, we made a list of popular log sources aggregated from many organizations. Admittedly, the list may end up being useless for organizations with different security needs and challenges. Joking aside, big organizations often make the decision to integrate a log source into their SIEM / UEBA based on factors other than the pure security necessity. Overall, such factors may include: And of course for users of those sad SIEM products that charge per gigabyte or EPS [oh… wait … this is still almost everybody! :-)], the cost of introducing a
One of the most common questions I received in my analyst years of covering SIEM and other security monitoring technologies was “what data sources to integrate into my SIEM first?” And of course the only honest answer to this question is: it depends on your security monitoring use cases and how you prioritize them. Naturally, some people then ask “ok, so then what are my use cases?” (and then there are these challenges too). Finally, perhaps in this paper, we made a list of popular log sources aggregated from many organizations. Admittedly, the list may end up being useless for organizations w
Explore this link on the map →