What is our primary use case?
I work on Identity Governance for this solution. We onboard the logs into the SIEM, into CrowdStrike Falcon, and we ensure that we get alerts on time and create dashboards using that data. Our work is basically log onboarding.
Everything is flowing compared to how long it was before. Probably in two minutes, you can get the data.
CrowdStrike Falcon Next-Gen SIEM is a very vast tool, and while we discussed it, it can be used for many purposes, but we are using it only for the log onboarding at this point. That solved my purpose and it really helps me in finding the root cause of an error or a problem. Logging into servers and finding out and tracing information on multiple servers is difficult. With a search field or query where you can filter, you can get the data instantly. That is great.
What is most valuable?
While we are onboarding our logs, we can see the timeline where the error was happening, and then we were able to troubleshoot following the timeline in the thread. The search was easy, and we were able to investigate and find the errors correctly.
It reduces the time to log in to servers to see what is going on since everything is in one place. We have multiple servers, so that saves a lot of time in not logging in.
CrowdStrike Falcon Next-Gen SIEM has a capability to scale very long, which I feel will continue with the new features that are coming out.
False positives and workload definitely have an impact on alert volume and analysis workload. It reduces stress and improves efficiency and tracking mechanisms. Trying to resolve things makes it efficient.
Alert volume is impacted. It is very interesting. Very recently, I have been using a browser in one of the servers and that triggered an alert immediately because we did not know what the browser was doing in the back-end. I could see that it is using its plug-in or its cookies or communicating with different various sites. I got an alert and was shocked to see what was going on in the back. I just loaded it, installed Chrome, and did not know what was going on. But when I got an alert, I saw that it was talking to Facebook, Google, and so many other things. Then I went there and looked at that alert, and then I uninstalled that browser immediately. That was incredible. I appreciate that feature.
The only thing which I worked on is log onboarding, so I stick to that. It gives a lot of information with respect to the metrics or KPIs based upon the SIEM because you onboard your logs and see various features from an application-wise, showing what has been implemented. Showing that in the application is difficult, but showing it in the SIEM is pretty easy based upon what we do. That stands out for the usage.
What needs improvement?
I do not use automations within CrowdStrike Falcon Next-Gen SIEM at this point, but that is something that we want to do in the future.
Maybe I did not experiment or did not investigate, but if we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything.
Actually, the circumstances that prompted my company to explore new SIEM solutions maybe include a point where the storage space or the license that we have, probably compared to other SIEM products, they have more, or the pricing and sales that go into the picture there. Again, that is above my pay grade to comment on, but it probably could be better if we can provide more storage of the data for the license that has been provided for organizations.
For how long have I used the solution?
I work as an IAM engineer and have ten years in my current field.
What do I think about the stability of the solution?
So far, the stability and reliability of CrowdStrike Falcon Next-Gen SIEM is good. From my use, it has been pretty solid. I appreciate that there are different ways of integration that you can provide. It is not a situation where it has to be in a format or a different format. It can take everything and then normalize it and show it in a way that a user can understand.
What do I think about the scalability of the solution?
CrowdStrike Falcon Next-Gen SIEM has a capability to scale very long, which I feel will continue with the new features that are coming out.
How are customer service and support?
Support from CrowdStrike is not relevant for me.
Which solution did I use previously and why did I switch?
There was Splunk before, and then it got migrated to CrowdStrike Falcon Next-Gen SIEM.
How was the initial setup?
I have not been involved in the deployment of CrowdStrike Falcon Next-Gen SIEM.
What about the implementation team?
The integration of CrowdStrike Falcon telemetry with other security data sources within the SIEM is something that the team can explain, but my usage is very limited.
What was our ROI?
I have definitely seen a return on my investment with this solution.
What's my experience with pricing, setup cost, and licensing?
Pricing, setup costs, and licensing of CrowdStrike Falcon Next-Gen SIEM is not my area.
Which other solutions did I evaluate?
There is Grafana, there is Dynatrace. There are many more SIEM tools that you can talk about. The only difference is the fact of looking at the thread and making graph relations and showing it visually. That stands out with CrowdStrike Falcon Next-Gen SIEM. But with respect to other tools, what is lacking, I do not know. Maybe I did not experiment or did not investigate, but if we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything.
What other advice do I have?
I have been attending some sessions to see how we can use CrowdStrike Falcon Next-Gen SIEM more. I appreciate the Charlotte AI, the agentic thing. Probably we will try to see what is going on there. The team is already doing the infrastructure management using CrowdStrike Falcon Next-Gen SIEM. That is not my expertise there, but there is something that I can still let the team know about this new development.
I just got to learn about Charlotte AI yesterday in the session, and that is very interesting where you can track the core workstation to actual incident and the adversaries. That is interesting. That is probably something that I want to explore.
CrowdStrike Falcon Next-Gen SIEM is a vast tool. It has everything from basic to advanced. The documentation is very vast, so that is one thing that you need to go through and try to understand, because the terminology used is niche.
In the majority, this is true. I am actually trying to clear a certification from CrowdStrike, so I am preparing for that. Learning through the documentation is much more useful. It is pretty nice. My overall rating for this solution is ten out of ten.