I would agree that besides the technology you also need the manpower behind it. And with regards to technology, you asked Securonix vs Arcsight. I would go with Arcsight, to gain the visibility into the logs first. I have worked with Arcsight for 8 years now as a partner and…
That is correct, you don't just install it and that is it. There is quite some work to do after installation
* You need to get events into the system, they need to be normalized, this is dependent upon the vendor and how they offer support for it. Again this is also…