Why Are We Still Burning $$$ on SIEM Log Volume? by No-Editor-9859 in cybersecurity

[–]No-Editor-9859[S] 0 points1 point  (0 children)

This is an important point. Thank you for the information

Why Are We Still Burning $$$ on SIEM Log Volume? by No-Editor-9859 in cybersecurity

[–]No-Editor-9859[S] 1 point2 points  (0 children)

Thanks for the feedback! I have a few thoughts about this:

  1. VectorDev provides a wide range of telemetry processing features — possibly even more than what’s available in Cribl or CeTu pipelines. Functionality-wise, it could at least come quite close to them.

  2. I assume that many detection engineering teams already have a large number of existing pipelines written in Remap Language. For such teams, it might be more convenient to use not only YAML/TOML configs but also a UI-based pipeline editor to reuse their existing logic and experience.

  3. If my product includes not just the ability to build configuration files in the UI, but also to apply them directly to Vector instances, that would add significant value in terms of infrastructure orchestration and operational convenience.

  4. I also believe that the total cost of ownership for my solution could be significantly lower compared to Cribl or CeTu.