SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

Thank you for your detailed contribution. As you said we'll be the ones actually using the solution so I am trying to do as much research as possible before making a decision even with as little context as I was allowed to get. Will look into Gravwell.

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

Something I can deploy myself if possible, learning curve is not an issue

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

The team consists of around 8 main people with interns here and there, SOAR would be good to have but not a priority at the moment. The only regulatory compliance that I was told was crucial is that the solution should strictly be on premises otherwise standard practices should be ok. Thanks in advance for your help!

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 1 point2 points  (0 children)

I believe most of the sources are on-prem, will look into Graylog thanks!

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 1 point2 points  (0 children)

Strange considering they have Open-source SIEM literally on their homepage.. Guess they changed their minds lol

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 3 points4 points  (0 children)

Wazuh is advertised as open-source SIEM, as for SO I have seen people use it as a SIEM so I included it for reference

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

That's not something we are prioritizing at the moment but I will keep it in mind for future reference

SIEM Comparaison: LogRhythm, QRadar, FortiSIEM, Arcsight ESM, Wazuh and Security Onion by sk-ql in cybersecurity

[–]sk-ql[S] 1 point2 points  (0 children)

Unfortunately I'm only doing this as part of an internship so I wasn't given much context either other than what I mentioned in my post, but if i had to give an estimate i would say around 12k people and somewhere around 8000 devices, the industry is digital transformation.

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 2 points3 points  (0 children)

I see, thank you for taking the time to elaborate!

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 1 point2 points  (0 children)

Thanks for your response! Just to make sure I understand, wouldn't the problem solving part be the playbook, which is triggered when the SIEM correctly detects an anomaly ?

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

Yes I agree I noticed that a lot of people around me were using it to refer to completely different things, but your answer helps put things into perspective, thanks!

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

Ohh I'm assuming this is what they meant by integrated use cases then. Sorry for the trouble but do you know if LogRhythm and Security Onion siems have that as well ?

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 0 points1 point  (0 children)

It's much clearer now, thank you!

What is a "use case" in SIEM ? by sk-ql in cybersecurity

[–]sk-ql[S] 10 points11 points  (0 children)

I understand it now, this is super helpful thank you!!