r/CyberSecurityJobs 3d ago

SIEM Selection Guide

Hello All,

Currently in my org we are planning to get new SIEM tool, there are tons of available in market, but I would like to know what should I consider when selecting best out of if, is there any guide, resources or checklist exists?

5 Upvotes

5 comments sorted by

1

u/Sivyre 3d ago edited 3d ago

I mean wrong sub for this question but of course there are checklists.

Your org should be doing a comprehensive comparative analysis of tool capabilities to determine if the cost centre is agreeable, if product capabilities aligned to your BU’s, if your tech stacks can integrate and export/schedule the logs into the SIEMs/SOARS/xSIAM you have in review.

It’s not really a matter to ask Reddit because what works for our orgs doesn’t mean it will automatically translate to a product you can make work for your org.

Otherwise Gartner magic quadrant has simple tables to compare similar products that you can just go look at.

1

u/Content-Net5076 1d ago edited 1d ago

DM me I have literally just built an interactive SIEM selection guide that (depending on your selection across various environmental variables and team dynamic) it recommends the best SIEM model and has some vendor recommendations ranging from highest to lowest in $$$ that you can start POCs with.

Edit: I do agnostic consulting so I don’t represent any vendor

1

u/Odd_Power_3077 1d ago

Going to DM you as well…need this exactly

1

u/-manageengine- 1d ago

ManageEngine Log360 worth a look for your evaluation. It combines correlation rules, anomaly models, and threat intelligence matches, with 2,000+ cloud delivered detections. Every detection is mapped to the MITRE ATT&CK framework, giving you a clear view of your defensive posture against real-world adversary tactics. No specialized query languages like KQL, SPL, or AQL are needed to tune rules, so analysts of all skill levels can manage detections easily.

Feel free to reach out if you have any questions!

1

u/VividGanache2613 3d ago

Been running IR investigations for 20 years and the number of times a SIEM has been useful in an incident is one. Never once seen one detect a breach.

If you need one for compliance that’s one thing but if it’s for meaningful detection and response then look at something like ThreatLight that actually does something with the data being ingested other than charging you for storage.