Enterprise Security Weekly (Audio)

SIEM: Shakeup in Event Management - What's Happening in the SIEM market today? - Jason Shockey, Seth Goldhammer - ESW #377

18 snips
Sep 27, 2024
Seth Goldhammer, VP at Greylog, sheds light on the SIEM market's transformation and the challenges it faces. Jason Shockey, founder of MyCyberPath.com, shares his passion for guiding cybersecurity career navigation. They discuss the evolving SIEM landscape, the critical role of situational awareness, and the impact of AI and machine learning. Shockey also emphasizes the importance of lifelong learning and personal attributes in cybersecurity careers. Anecdotes and insights make for a rich conversation on both current trends and future possibilities.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

SIEM Evolution Beyond Compliance

  • Log collection alone is a commodity; real SIEM value lies in active analytics and applying use cases.
  • Compliance kept SIEMs alive but true security focus has returned with evolving SOC roles.
INSIGHT

SIEM Log Cost Challenges

  • SIEM pricing models often charge equally for all logs regardless of value, creating inefficiencies.
  • A smarter SIEM differentiates actionable logs from standby logs, reducing costs while maintaining coverage.
ADVICE

Use Case First SIEM Approach

  • Start SIEM implementation from use cases to define required analytics and then determine needed logs.
  • Avoid collecting all data blindly to prevent overwhelmed systems and unclear objectives.
Get the Snipd Podcast app to discover more snips from this episode
Get the app