flâneur — a map of the web's best reading

Left of SIEM? Right of SIEM? Get It Right! | by Anton Chuvakin | Anton on Security | Medium

medium.com · saved by 1 readers

This post is perhaps a little basic for true SIEM literati, but it covers an interesting idea about SIEM’s role in today’s security. I suspect that this topic will become even more fascinating in light of the appearance of XDR — but more on this a bit later… So let’s talk about what’s to the left and to the right of SIEM. Note that this has nothing to do with the “shift left” of software development. Well, it has nothing to do with it directly, but perhaps there are lessons to be learned in this area for our domain. Your SIEM looks at certain inputs and produces some outputs (this is not all about GIGO, BTW). But, yes, if the inputs are dirty and/or the outputs drop on the floor, SIEM cannot succeed, no matter what the SIEM vendor says or does. When I say that somebody succeeded with SIEM, it often implies that they got things to the left of SIEM and to the right of SIEM right or at least “right enough.” It is not enough - absolutely, not enough! — to just install your SIEM software co

This post is perhaps a little basic for true SIEM literati, but it covers an interesting idea about SIEM’s role in today’s security. I suspect that this topic will become even more fascinating in light of the appearance of XDR — but more on this a bit later… So let’s talk about what’s to the left and to the right of SIEM. Note that this has nothing to do with the “shift left” of software development. Well, it has nothing to do with it directly, but perhaps there are lessons to be learned in this area for our domain. Your SIEM looks at certain inputs and produces some outputs (this is not all a

Explore this link on the map →