The Two-Headed SIEM Monster - by Omer Singer
The government defines SIEM as “a single system to improve the detection and remediation of security issues,” but what happens when you have more than one? The SIEM’s role as the place where security events get centralized has eroded as security data exploded simultaneously as analytics requirements for large SOCs became more sophisticated. Now, emerging trends are transforming the problem from too many silos to too many SIEMs. This spells trouble for security operations, where two heads are not at all better than one. Let’s unpack the trends pushing SOCs to rely on multiple SIEMs. We’ll see that these powerful currents will likely shape security operations for years to come. First, what do all the Gartner EDR MQ leaders have in common? Under the banner of XDR, they’ve all started selling SIEM. CrowdStrike says we’ve got Next-Gen SIEM and Log Management Microsoft will sell you An easy and powerful SIEM solution Palo Alto didn’t like that others copied “XDR” so they called their SIEM by
The Two-Headed SIEM Monster Industry trends point to multiple SIEMs becoming a wider problem for security operations Omer Singer Feb 08, 2024 4 Share The government defines SIEM as “a single system to improve the detection and remediation of security issues,” but what happens when you have more than one? The SIEM’s role as the place where security events get centralized has eroded as security data exploded simultaneously as analytics requirements for large SOCs became more sophisticated. Now, emerging trends are transforming the problem from too many silos to too many SIEMs. This spells troubl
Explore this link on the map →related reading
- Is the SIEM dead? - CPO Magazinecpomagazine.com
- No Vendor Consolidation In The SOC - by SACRsoftwareanalyst.substack.com
- Security is about data: how different approaches are fighting for security data and what the cybersecurity data stack of the future is shaping up to look likeventureinsecurity.net
- Mediumblog.snapattack.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Protect your organization as SIEM vendor, technology and threat landscape changeslinkedin.com
- Why did we need to build our own SIEM?rippling.com
- SIEM shakeup: IBM retreats, Splunk sold and the fate of the rest - SDxCentralsdxcentral.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- Report: The Era of Endpoints | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Security Data Pipelines for AI-Powered SIEM | SentinelOneobservo.ai