ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Security Information Event Management (SIEM)

    IT Discussion
    13
    32
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @JaredBusch
      last edited by

      @JaredBusch said in Security Information Event Management (SIEM):

      @IRJ said in Security Information Event Management (SIEM):

      @JaredBusch said in Security Information Event Management (SIEM):

      @IRJ said in Security Information Event Management (SIEM):

      I'm surprised nobody has mentioned elastic yet.

      There's an open source version and a free version (more features).

      I did not mention it intentionally.

      Because it is too complex to use as a SEIM unless you already know a lot about it.

      Elastic basic (free) is pretty simple. Open Source version requires a bit more knowledge and integration

      Setting up Elastic to ingest some basic logs? Simple. Setting up a SEIM with Elastic? Not so much.

      This. As straight log management, it's some effort, but like, half a day tops. SEIM with it, though, is an undertaking on top of that.

      1 Reply Last reply Reply Quote 1
      • hobbit666H
        hobbit666 @JaredBusch
        last edited by

        @JaredBusch said in Security Information Event Management (SIEM):

        This is not because Elastic is bad, it is because it is complex.

        Agreed, it's a beast of a system.
        The SIEM part requires a "Basic" license, but seems to be around $200 / year.

        1 Reply Last reply Reply Quote 0
        • hobbit666H
          hobbit666
          last edited by

          What pricing are we looking at for other solution like
          Arctic Wolf?
          Rapid 7?
          Azure Sential?

          (Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.)

          1 dbeatoD 2 Replies Last reply Reply Quote 0
          • 1
            1337 @hobbit666
            last edited by 1337

            @hobbit666 said in Security Information Event Management (SIEM):

            Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.

            They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out, because they wont state their price.

            A simple "from $xyz per month" would suffice.

            DashrenderD 1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @1337
              last edited by

              @Pete-S said in Security Information Event Management (SIEM):

              @hobbit666 said in Security Information Event Management (SIEM):

              Hate companies that don't show pricing, as if they are in £££££ range, the demo wont be install or tried.

              They don't understand that they are losing business. They think they are getting leads into their sales funnel by not giving the price and forcing people to contact them. In reality some of their leads are actually dropping out just, because they wont state their price.

              A simple "from $xyz per month" would suffice.

              Agreed - I'm sure they lose more leads than they gain this way...

              1 Reply Last reply Reply Quote 1
              • dbeatoD
                dbeato @hobbit666
                last edited by

                @hobbit666 ArticWolf is around 30k per site.

                hobbit666H 1 Reply Last reply Reply Quote 0
                • hobbit666H
                  hobbit666 @dbeato
                  last edited by hobbit666

                  @dbeato said in Security Information Event Management (SIEM):

                  @hobbit666 ArticWolf is around 30k per site.

                  I'll Learn Elastic instead 😄

                  1 Reply Last reply Reply Quote 0
                  • nadnerBN
                    nadnerB
                    last edited by

                    SIEM is expensive. So if you go paid, prepare a seriously good business case.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      JasGot @nadnerB
                      last edited by

                      @nadnerB said in Security Information Event Management (SIEM):

                      SIEM is expensive. So if you go paid, prepare a seriously good business case.

                      That's the easy part. Corporate Mandate.

                      1 Reply Last reply Reply Quote 3
                      • hobbit666H
                        hobbit666
                        last edited by

                        Everything we do here as a good business case. Just the board don't see the same lol

                        1 Reply Last reply Reply Quote 0
                        • ObsolesceO
                          Obsolesce
                          last edited by

                          You can also do a 31 day trial of Azure Sentinel to get a feel for how much data it may consume. You can also try Azure Monitor to get a feel for the data needs. Choosing the pay as you go option for both.

                          How much data per day do you imagine?

                          You need to account for both Sentinel and Azure Monitor.

                          hobbit666H 1 Reply Last reply Reply Quote -1
                          • hobbit666H
                            hobbit666 @Obsolesce
                            last edited by

                            @Obsolesce said in Security Information Event Management (SIEM):

                            How much data per day do you imagine?

                            For me no idea.

                            1 Reply Last reply Reply Quote 0
                            • larsen161L
                              larsen161
                              last edited by

                              A previous colleague of mine just joined https://www.claroty.com/ which I just started to check out. I have not used it though

                              1 Reply Last reply Reply Quote 0
                              • 1
                              • 2
                              • 2 / 2
                              • First post
                                Last post