Today, You Really Want a SaaS SIEM! | by Anton Chuvakin | Anton on Security | Medium
One thing I did not expect to see in 2021 is a lot of people complaining about how difficult their SIEM is to operate. Let’s explore this topic for the (n+1)-th time. And let me tell you … that “n” is pretty damn large since my first involvement with SIEM in January 2002 (!) — examples, examples, examples. (source, date: 2012) Before we go, we need to separate the SIEM tool operation difficulties from the SIEM mission difficulties. To remind, the mission that the SIEM is aimed at is very difficult in today’s environments. The mission also evolved a lot over the years from alert aggregation to compliance and reporting to threat detection and response support. Note that even intelligently aggregating, cleaning and normalizing lots of logs coming from a broad range of systems, from mainframes to microservices is not that easy… With that out of the way, SIEM detection challenges definitely do not mean that you need to spend hours patching a SIEM appliance, for example. Or tuning the backen
4 min read Apr 9, 2021 -- One thing I did not expect to see in 2021 is a lot of people complaining about how difficult their SIEM is to operate. Let’s explore this topic for the (n+1)-th time. And let me tell you … that “n” is pretty damn large since my first involvement with SIEM in January 2002 (!) — examples, examples, examples. Anton’s old SIEM presentation from 2012 (source, date: 2012) Before we go, we need to separate the SIEM tool operation difficulties from the SIEM mission difficulties. To remind, the mission that the SIEM is aimed at is very difficult in today’s…
related reading
- The Two-Headed SIEM Monster - by Omer Singeromeronsecurity.com
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Is the SIEM dead? - CPO Magazinecpomagazine.com
- The Great Splunkbundlingrakgarg.substack.com
- Why did we need to build our own SIEM?rippling.com
- Mediumblog.snapattack.com
- SIEM 4.0: The Essentialist Evolutionjacknaglieri.substack.com
- Is this the end of SIEM?franklyspeaking.substack.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Survivor's Guide to SIEM in 2024omeronsecurity.com
- Top Content on LinkedInlinkedin.com