The Security Data Fabric Identity Crisis - by Omer Singer
Big changes are happening to how security teams get their data. For years, data collection was a function of the SIEM. Splunk’s app store, for example, includes hundreds of supported connectors that integrate with everything from firewalls to vulnerability scanners. In parallel, large SOCs formed teams to manage open-source pipelines for shaping and routing data using technologies like Apache Kafka and NiFi. Security organizations have now reached a tipping point for their data. On one side are the three V’s of data explosion: volume, velocity, and variety. Security teams are dealing with an avalanche of logs from endpoint agents, multi-cloud hybrid infrastructure, distributed workforces, and SaaS applications. Information must be collected from within the environment and from outside via APIs. It’s also more valuable than ever, with advances in AI enabling new insights on risks and threats. Add “value” as a fourth V driving the need for data pipeline investment. Subscribed On the othe
Tara Moore/Getty Images Big changes are happening to how security teams get their data. For years, data collection was a function of the SIEM. Splunk’s app store, for example, includes hundreds of supported connectors that integrate with everything from firewalls to vulnerability scanners. In parallel, large SOCs formed teams to manage open-source pipelines for shaping and routing data using technologies like Apache Kafka and NiFi. Connectors coupled with SIEM Security organizations have now reached a tipping point for their data. On one side are the three V’s of data explosion: volume,…
related reading
- The Security Data Fabric Identity Crisisomeronsecurity.com
- Security is about data: how different approaches are fighting for security data and what the cybersecurity data stack of the future is shaping up to look likeventureinsecurity.net
- The Evolution of the Modern Security Data Platformsoftwareanalyst.substack.com
- What I Learned From The Modern Data Stack Conference 2021 - James Lejameskle.com
- Protect your organization as SIEM vendor, technology and threat landscape changeslinkedin.com
- The Transition from Monolithic SIEMs to Data Lakes for Security Monitoringjacknaglieri.substack.com
- The Splunk Effectomeronsecurity.com
- The Great Splunkbundlingrakgarg.substack.com
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- Bringing Digital Transformation to Cybersecuritylinkedin.com
- The Two-Headed SIEM Monster - by Omer Singeromeronsecurity.com
- Survivor's Guide to SIEM in 2024omeronsecurity.com