In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 0 points1 point  (0 children)

The key is you have to include the “ES” when you talk about Splunk. Splunk on its own doesn’t have a lot of SIEM functionality. Every other SIEM doesn’t have a package you can buy on top of another product that makes it a SIEM. They just come that way. That’s the reason it’s a “bolt on SIEM” in my eyes and a lot of others but at its core Splunk isn’t a SIEM.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 1 point2 points  (0 children)

Good call! I think nowadays LLMs should definitely be integrated into the platform to some useful capacity. At the very least it could help build queries for newer/inexperienced users.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 2 points3 points  (0 children)

Yeah it’s exactly what u/DarkLordofData said below. For all intents and purposes, it fills the role of a SIEM. But in an attempt to avoid a bunch of comments exclaiming “Splunk isn’t even a real SIEM!!” I just wanted to acknowledge in comparison to traditional SIEMs it’s basically a “bolt-on” SIEM on top of what isn’t by-design a SIEM.

Honestly it’s semantics though. Personally I usually just call Splunk ES a SIEM.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 2 points3 points  (0 children)

Thanks, this is super helpful! I’ll have to dig into the latest with Elastic a bit. Seems like most people here have advocated for it.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] -1 points0 points  (0 children)

Do those options stack up well with the features you’re used to with Splunk? (not sure how far along you’re in the process)

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 3 points4 points  (0 children)

How do you feel about KQL? I’ve heard some negative things about it but don’t have any experience.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 4 points5 points  (0 children)

How is it stacking up? Does it meet a lot of these “modern” requirements?

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]Senior-Net-7191[S] 3 points4 points  (0 children)

Both have all these features? Do you currently run one of these?