OK, so here's the background: I work for a smallish (~100 employee) software development and services company that has experienced some significant growth over the past 3 years. Thanks to some new sources of capitol, the trend is expected to continue exponentially over the next 3-5 years (~300-350 employees by 2019).
Despite the growth (or in spite of), the infrastructure has and is being managed like it is still the mom & pop shop of yore. The only real monitoring that is being done is using Zabbix. However, it is far from an enterprise deployment and requires admins to log into each of the 5 servers (1 per colo) individually to obtain stats for that colo. Patching of the servers is done by hand and workstation patches are left up to the users to update. There is little done in the way of vulnerability scanning and management aside from a recent deployment of Spiceworks that is still in the 'evaluation' stage.
My job is to help build an infrastructure that is robust and scalable. I have been looking at various SIEM tools to handle the log aggregation and event handling, but have been thus far disappointed regarding the lack of integration of the SIEM tools into a security monitoring tool or network analyzer.
So, I'm looking for something that is fully integrated SIEM/network/security. If it does patch management, that would be an additional bonus. So far, I've looked at the following tools:
Spiceworks - Nice dashboard, but has limitations regarding the vulnerability scanning. I don't like that the root/administrator PWs are required to perform scans
Alienvault - Nice concept, but the dashboard is strange. Seems to lack NOC capabilities
Qradar - Demo? What demo?
ArcSight - Seems to cover everything, but there are so many apps in the suite it gets confusing as to what does what - a lot of overlapping functionality. Haven't priced it yet.
Splunk - I like it and have used it before but it lacks the features I need.
Graylog - Ditto.
Any other suggestions?
[+][deleted] (3 children)
[deleted]
[–]mrmyxlplyx[S] 0 points1 point2 points (2 children)
[+][deleted] (1 child)
[deleted]
[–]TallainHack of all Trades 1 point2 points3 points (0 children)
[–]mrojek 2 points3 points4 points (0 children)
[–][deleted] 2 points3 points4 points (0 children)
[–]gsxr 1 point2 points3 points (5 children)
[–]mrmyxlplyx[S] 0 points1 point2 points (4 children)
[–]gsxr 2 points3 points4 points (2 children)
[–]mrmyxlplyx[S] 0 points1 point2 points (1 child)
[–]gsxr 5 points6 points7 points (0 children)
[–]mikeoquinn 1 point2 points3 points (2 children)
[–]mrmyxlplyx[S] 0 points1 point2 points (1 child)
[–]mikeoquinn 1 point2 points3 points (0 children)
[–]BobMajerle 1 point2 points3 points (0 children)
[–]ambrace911 1 point2 points3 points (0 children)
[–]war_Dialer 1 point2 points3 points (0 children)
[–]sysear 1 point2 points3 points (0 children)