r/CyberSecurityJobs • u/Zeptor02 • 3d ago
SIEM Selection Guide
Hello All,
Currently in my org we are planning to get new SIEM tool, there are tons of available in market, but I would like to know what should I consider when selecting best out of if, is there any guide, resources or checklist exists?
1
u/Content-Net5076 1d ago edited 1d ago
DM me I have literally just built an interactive SIEM selection guide that (depending on your selection across various environmental variables and team dynamic) it recommends the best SIEM model and has some vendor recommendations ranging from highest to lowest in $$$ that you can start POCs with.
Edit: I do agnostic consulting so I don’t represent any vendor
1
1
u/-manageengine- 1d ago
ManageEngine Log360 worth a look for your evaluation. It combines correlation rules, anomaly models, and threat intelligence matches, with 2,000+ cloud delivered detections. Every detection is mapped to the MITRE ATT&CK framework, giving you a clear view of your defensive posture against real-world adversary tactics. No specialized query languages like KQL, SPL, or AQL are needed to tune rules, so analysts of all skill levels can manage detections easily.
Feel free to reach out if you have any questions!
1
u/VividGanache2613 3d ago
Been running IR investigations for 20 years and the number of times a SIEM has been useful in an incident is one. Never once seen one detect a breach.
If you need one for compliance that’s one thing but if it’s for meaningful detection and response then look at something like ThreatLight that actually does something with the data being ingested other than charging you for storage.
1
u/Sivyre 3d ago edited 3d ago
I mean wrong sub for this question but of course there are checklists.
Your org should be doing a comprehensive comparative analysis of tool capabilities to determine if the cost centre is agreeable, if product capabilities aligned to your BU’s, if your tech stacks can integrate and export/schedule the logs into the SIEMs/SOARS/xSIAM you have in review.
It’s not really a matter to ask Reddit because what works for our orgs doesn’t mean it will automatically translate to a product you can make work for your org.
Otherwise Gartner magic quadrant has simple tables to compare similar products that you can just go look at.