Enterprise Security Weekly (Audio) SIEM: Shakeup in Event Management - What's Happening in the SIEM market today? - Jason Shockey, Seth Goldhammer - ESW #377
18 snips
Sep 27, 2024 Seth Goldhammer, VP at Greylog, sheds light on the SIEM market's transformation and the challenges it faces. Jason Shockey, founder of MyCyberPath.com, shares his passion for guiding cybersecurity career navigation. They discuss the evolving SIEM landscape, the critical role of situational awareness, and the impact of AI and machine learning. Shockey also emphasizes the importance of lifelong learning and personal attributes in cybersecurity careers. Anecdotes and insights make for a rich conversation on both current trends and future possibilities.
AI Snips
Chapters
Transcript
Episode notes
SIEM Evolution Beyond Compliance
- Log collection alone is a commodity; real SIEM value lies in active analytics and applying use cases.
- Compliance kept SIEMs alive but true security focus has returned with evolving SOC roles.
SIEM Log Cost Challenges
- SIEM pricing models often charge equally for all logs regardless of value, creating inefficiencies.
- A smarter SIEM differentiates actionable logs from standby logs, reducing costs while maintaining coverage.
Use Case First SIEM Approach
- Start SIEM implementation from use cases to define required analytics and then determine needed logs.
- Avoid collecting all data blindly to prevent overwhelmed systems and unclear objectives.
