Security Information Event Management (SIEM)
-
We use Dell SecureWorks MDR. Has been good so far. We get quarterly meetings and whenever anything questionable is seen in logs/scans/user usage, we are contacted.
-
I'm surprised nobody has mentioned elastic yet.
There's an open source version and a free version (more features).
-
Alienvault (Paid) / OSSIM (Free). We use the paid version here. It's a bit cumbersome to work with, but gives a lot of good details IMO.
-
@IRJ said in Security Information Event Management (SIEM):
I'm surprised nobody has mentioned elastic yet.
There's an open source version and a free version (more features).
I did not mention it intentionally.
Because it is too complex to use as a SEIM unless you already know a lot about it.
-
@JaredBusch said in Security Information Event Management (SIEM):
Because it is too complex to use as a SEIM unless you already know a lot about it.
Agreed, i've been looking at it for checking over logs from all our servers. But one minutes it's workign fine then boom errors all over the place . So need to look for a new system myself for this and log management
-
@JasGot Yes, that is what I meant.
-
Wow! What an excellent response!
Thank you to everyone. I'll start exploring these and report back. -
@hobbit666 said in Security Information Event Management (SIEM):
But one minutes it's workign fine then boom errors all over the place
This is not because Elastic is bad, it is because it is complex. Which is why it is a poor solution for people like @JasGot
Unless a person has the time to really learn elastic and how to do things well, it jsut turns into a mess.
-
@JaredBusch said in Security Information Event Management (SIEM):
@IRJ said in Security Information Event Management (SIEM):
I'm surprised nobody has mentioned elastic yet.
There's an open source version and a free version (more features).
I did not mention it intentionally.
Because it is too complex to use as a SEIM unless you already know a lot about it.
Elastic basic (free) is pretty simple. Open Source version requires a bit more knowledge and integration
-
-
@IRJ said in Security Information Event Management (SIEM):
@JaredBusch said in Security Information Event Management (SIEM):
@IRJ said in Security Information Event Management (SIEM):
I'm surprised nobody has mentioned elastic yet.
There's an open source version and a free version (more features).
I did not mention it intentionally.
Because it is too complex to use as a SEIM unless you already know a lot about it.
Elastic basic (free) is pretty simple. Open Source version requires a bit more knowledge and integration
Setting up Elastic to ingest some basic logs? Simple. Setting up a SEIM with Elastic? Not so much.
-
@JaredBusch said in Security Information Event Management (SIEM):
This is not because Elastic is bad, it is because it is complex. Which is why it is a poor solution for people like @JasGot
Unless a person has the time to really learn elastic and how to do things well, it jsut turns into a mess.Yea, I'm not in the mood to learn something that complex for a one off.
-
@JaredBusch said in Security Information Event Management (SIEM):
@IRJ said in Security Information Event Management (SIEM):
@JaredBusch said in Security Information Event Management (SIEM):
@IRJ said in Security Information Event Management (SIEM):
I'm surprised nobody has mentioned elastic yet.
There's an open source version and a free version (more features).
I did not mention it intentionally.
Because it is too complex to use as a SEIM unless you already know a lot about it.
Elastic basic (free) is pretty simple. Open Source version requires a bit more knowledge and integration
Setting up Elastic to ingest some basic logs? Simple. Setting up a SEIM with Elastic? Not so much.
This. As straight log management, it's some effort, but like, half a day tops. SEIM with it, though, is an undertaking on top of that.
-
@JaredBusch said in Security Information Event Management (SIEM):
This is not because Elastic is bad, it is because it is complex.
Agreed, it's a beast of a system.
The SIEM part requires a "Basic" license, but seems to be around $200 / year. -
What pricing are we looking at for other solution like
Arctic Wolf?
Rapid 7?
Azure Sential?(Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.)
-
@hobbit666 said in Security Information Event Management (SIEM):
Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.
They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out, because they wont state their price.
A simple "from $xyz per month" would suffice.
-
@Pete-S said in Security Information Event Management (SIEM):
@hobbit666 said in Security Information Event Management (SIEM):
Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.
They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out just, because they wont state their price.
A simple "from $xyz per month" would suffice.
Agreed - I'm sure they lose more leads than they gain this way...
-
@hobbit666 ArticWolf is around 30k per site.
-
@dbeato said in Security Information Event Management (SIEM):
@hobbit666 ArticWolf is around 30k per site.
I'll Learn Elastic instead
-
SIEM is expensive. So if you go paid, prepare a seriously good business case.