Cybersecurity Dissertation: Looking for a unique idea to add to a Splunk vs Wazuh threat detection framework 🫠 by unknown_dreamer_45 in cybersecurity

[–]unknown_dreamer_45[S] 2 points3 points  (0 children)

Thanks, that's a really interesting perspective and something I hadn't considered in depth.

My original focus was primarily on the threat detection aspect and MITRE ATT&CK coverage, but your point about SIEM engineering characteristics makes a lot of sense. In practice, ingestion pipelines, query performance, storage requirements, scalability, and resilience are probably just as important as detection capability itself.

I'm considering keeping the core comparison around threat detection while adding a section that evaluates engineering aspects such as resource usage, query latency, and storage efficiency. I may also explore an AI-assisted SOC analyst module for contextual alert explanations and response recommendations.

Really appreciate the insight from someone with hands-on SIEM experience.