Security Information and Event Management (SIEM) Questions
Jan 17 2022
Are you aware of SIEM platforms that integrate both Active Directory auditing and security monitoring tools?
Usually, when professionals administer the network, they use an Active Directory tool and a cybersecurity solution (e.g., EPP, anti-virus, or SIEM) separately.
Are you aware of SIEM platforms that integrate these tools?
Dec 13 2021
Hi infosec professionals,
Which deployment model should an enterprise organization choose and in which case?
Nov 24 2021
When would you suggest using an internal SOC and when SOC-as-a-Service? What are the pros and cons of each?
Nov 24 2021
I'm working on a document about the Security Operation Center best practices, and I would like to get your inputs about it.
Sep 25 2021
Have you tried Google Chronicle? What's your opinion about it?
Oct 05 2021
What are your methods to automate Azure Sentinel content deployment?
Are you adopting a Detection-As-Code approach? What main challenges have you faced?
Thank you in advance!
Sep 13 2021
Hot data is necessary for live security monitoring. Archive data (cold data) is not available fastly. It takes days to make archive data live if the archive data time frame is more than 30 days (in most of the SIEM solutions). As an example, SolarWinds said the attackers first compromised its... Read More »
Aug 27 2021
What is the best way to deploy agents/sensors (such as a SIEM agent) in large-scale Windows environments?
Any hands-on tips or recommendations?
Sep 03 2021
When one writes detection rules for SIEM solutions, what are the criteria of a good detection rule?
Can you share any examples?
Aug 24 2021
Once a SIEM is deployed successfully, what are the top use cases you'd recommend to implement for the Microsoft environment?
Thank you in advance!
Aug 10 2021
Which SIEM for small/medium-sized companies do you consider the most economical?
Splunk, Security Onion, UTMStack, other? What do you like about it vs other ones?
Aug 12 2021
Is Rapid7 InsightIDR an efficient solution (to be used in SOC as an analysis tool) in comparison with other SIEM products, such as IBM QRadar, Splunk, and LogRhythm NextGen SIEM?
Aug 27 2021
Hi community members,
Let's discuss what are the main differences between UEBA (User and Entity Behavior Analytics) and SIEM (Security Information and Event Management) solutions.
Sep 08 2021
Hi community, We would like to hear your insights on the latest trends in SOC. What are you seeing in the field or forecasting? Please share your opinion on how these trends are going to influence the future of the relevant solutions, tools, etc. used in SOC. Looking forward to hearing your... Read More »
Hi, I'm looking for a technical comparison between Splunk Phantom SOAR and FireEye SOAR solutions.
Can anyone help with insights?
Aug 09 2021
I have slowly switched our entire network over to Fortinet products over the past few years and been pleased with the products overall. I would like to utilize FortiSIEM for more robust monitoring and response, but the cost is extremely prohibitive for my company (<25 employees). Suggestions? Read More »
There are many cybersecurity tools available, but some aren't doing the job that they should be doing. What are some of the threats that may be associated with using 'fake' cybersecurity tools? What can people do to ensure that they're using a tool that actually does what it says it does? Read More »
Aug 09 2021
How do log management and SIEM differ? Is it necessary to have separate tools for each function or can these functions be rolled into one solution? Which products are best for SIEM, and which are better for log management? Do you have recommendations of products that effectively combine both log... Read More »
Sep 07 2021
What are the differences between how NDR and SIEM work?
What are the pros and cons of each? Is it necessary to have both types of tools?
Dec 17 2021
Can anyone advise on which SIEM will work best with Palo Alto Cortex XDR?
Nov 16 2021
I work at mid-sized enterprise bank. I am researching SIEM solutions. Which is the best tool for security information and event management: Arcsight or Securonix?
Aug 31 2021
SIEM and SOAR have a lot of components in common. How do they differ in the role they play in Cyber Security? If you've been working in cybersecurity, you've likely come across SOAR and SIEM technologies. There are differences between their capabilities, although they have a fair amount of commo... Read More »
Are event correlation and aggregation both needed for effective event monitoring and SIEM?
Oct 29 2021
I am the technical director of a science and technology division for the government.
Which SIEM solution would deliver the best ability to identify, protect, detect, respond and recover from a cyber attack?
Thanks! I appreciate your help.
Jul 26 2021
Hi dear community members, There's a lot of SIEM solutions. SIEMs are not something you just install and wait for great things to happen, right? What questions should someone ask before purchasing a SIEM? Help your peers ask the right questions so that they'll make the best decision. Thanks Read More »
Nov 01 2021
There are so many SIEM solutions out there and so much vendor hype in the market. Conducting an effective trial is really important! A number of community members are currently evaluating solutions. Do you have any advice for them about the best way to conduct a trial or POC? How do you cond... Read More »
Product CategoriesSecurity Information and Event Management (SIEM)
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Trustwave, Splunk, IBM, and more!
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Questions Should I Ask Before Buying SIEM?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- What is the difference between SIEM and SOAR platforms?
- How does Network Detection and Response (NDR) Differ from SIEM?
- What is the difference between log management and SIEM?