Security Information Event Management (SIEM)
-
@JaredBusch said in Security Information Event Management (SIEM):
This is not because Elastic is bad, it is because it is complex.
Agreed, it's a beast of a system.
The SIEM part requires a "Basic" license, but seems to be around $200 / year. -
What pricing are we looking at for other solution like
Arctic Wolf?
Rapid 7?
Azure Sential?(Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.)
-
@hobbit666 said in Security Information Event Management (SIEM):
Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.
They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out, because they wont state their price.
A simple "from $xyz per month" would suffice.
-
@Pete-S said in Security Information Event Management (SIEM):
@hobbit666 said in Security Information Event Management (SIEM):
Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.
They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out just, because they wont state their price.
A simple "from $xyz per month" would suffice.
Agreed - I'm sure they lose more leads than they gain this way...
-
@hobbit666 ArticWolf is around 30k per site.
-
@dbeato said in Security Information Event Management (SIEM):
@hobbit666 ArticWolf is around 30k per site.
I'll Learn Elastic instead
-
SIEM is expensive. So if you go paid, prepare a seriously good business case.
-
@nadnerB said in Security Information Event Management (SIEM):
SIEM is expensive. So if you go paid, prepare a seriously good business case.
That's the easy part. Corporate Mandate.
-
Everything we do here as a good business case. Just the board don't see the same lol
-
You can also do a 31 day trial of Azure Sentinel to get a feel for how much data it may consume. You can also try Azure Monitor to get a feel for the data needs. Choosing the pay as you go option for both.
How much data per day do you imagine?
You need to account for both Sentinel and Azure Monitor.
-
@Obsolesce said in Security Information Event Management (SIEM):
How much data per day do you imagine?
For me no idea.
-
A previous colleague of mine just joined https://www.claroty.com/ which I just started to check out. I have not used it though