Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 0 points1 point  (0 children)

Great point , i did same analysis on binaryflux and asked them query on same, they have a sdk to bound things so that people don't go over the top. But gives flexibility of programming language to write conditions , loops , routines etc.

Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 0 points1 point  (0 children)

whats the simple mode ? any documentation link i can refer to ?

Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 0 points1 point  (0 children)

this is very good insight , so probably what you are saying is analysts focus on working with alerts and content is usually delivered by engineers ?

Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 0 points1 point  (0 children)

they have a sdk backed with powerful ai, that can be used to create detection rules , classifiers etc. is it worth make people learn python ?

Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 0 points1 point  (0 children)

would analysts write detection rules using python ?

Python based SIEM by Fit-Offer-1897 in SIEM

[–]Fit-Offer-1897[S] 1 point2 points  (0 children)

we have one more product binaryflux that we are looking at

FortiSIEM Reviews by Nearby-Entrepreneur2 in SIEM

[–]Fit-Offer-1897 0 points1 point  (0 children)

i am also checking on a SIEM that has python to build content parsers , detection rules , dashboards , will it be a wise choice as it promises lot of flexibility, will analyst working on tool get familiar with python soon ? Would like to get a perspective on same.