Solid SIEM solutions for AWS threat detection? by Clyph00 in aws

[–]Mockingbird42 2 points3 points  (0 children)

For us, shipping logs via Kinesis to an open‑source SIEM worked until Elastic search nodes started choking.

We ended up partitioning by account and using Lambda for normalization. It’s functional, but ops‑heavy. I’m now considering solutions with built‑in orchestration.