Survivor's Guide to SIEM in 2024 - by Omer Singer
This isn’t another post about the morning of May 15, when IBM Qradar customers learned that the company was exiting the SIEM business. They could start from scratch with Palo Alto Networks’ XSIAM product or something else entirely. You don’t have to go home, but you can’t stay here. Industry pundits have been discussing the news ad nauseam, so I won’t rehash why these products hit a wall and whether those were savvy business deals. Instead, I present how an ownership mindset can prepare your organization for what comes next. So far, the biggest progress towards breaking lock-in and taking ownership has been around data pipelines. In the past, data collection tooling was seen as an integral part of SIEM. Splunk has Universal Forwarders, Securonix has Remote Ingestion Nodes, etc. Typical enterprise deployments include thousands of agents installed on servers and networks throughout the organization. The many-to-one approach became less popular as demand grew for multiple pipeline destina
Source: Bethesda Softworks This isn’t another post about the morning of May 15, when IBM Qradar customers learned that the company was exiting the SIEM business. They could start from scratch with Palo Alto Networks’ XSIAM product or something else entirely. You don’t have to go home, but you can’t stay here. Industry pundits have been discussing the news ad nauseam, so I won’t rehash why these products hit a wall and whether those were savvy business deals. Instead, I present how an ownership mindset can prepare your organization for what comes next. So far, the biggest progress towards…
related reading
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- As Palo Alto Networks Absorbs IBM QRadar, Traditional SIEM Is Fading: Analysiscrn.com
- The Evolution of the Modern Security Data Platformsoftwareanalyst.substack.com
- Security is about data: how different approaches are fighting for security data and what the cybersecurity data stack of the future is shaping up to look likeventureinsecurity.net
- IBM Surrenders SIEM While PANW Tries To Gain On Tech Titansforrester.com
- SIEM shakeup: IBM retreats, Splunk sold and the fate of the rest - SDxCentralsdxcentral.com
- Is the SIEM dead? - CPO Magazinecpomagazine.com
- Mediumblog.snapattack.com
- Is this the end of SIEM?franklyspeaking.substack.com
- The Great Splunkbundlingrakgarg.substack.com
- Protect your organization as SIEM vendor, technology and threat landscape changeslinkedin.com
- No Vendor Consolidation In The SOC - by SACRsoftwareanalyst.substack.com