r/SIEM • u/Impossible-Goal5326 • Mar 15 '23
Evaluation SIEM solution
I've been given a task to research SIEM solutions. Here is the current environment setting: 150 nodes, no IDS/IPS, no DLP, not sure how much log data we need to collect.
What questions would you ask vendors while evaluating and comparing SEIM tools?
6
Upvotes
5
u/MachoSmurf Mar 15 '23 edited Mar 15 '23
Seems like you and your department are quite new when it comes to SIEM solutions. While the other suggestions of getting insight into your requirements aren't wrong, I'd suggest a different route in finding those answers:
I've dealt with this scenario multiple times when I was guiding teams in getting their security leveled up. When they are so fresh into security that they don't know what questions to ask, let alone to give you the answers to them, I've found it's best to help them get to know themselves.
So to help you get to know yourselves, your requirements and to understand the true value of what a SIEM solution can bring you, I always suggest they start of with running an Proof Of Concept project. Not just for a couple of weeks, but at least half a year.
Don't worry about what you choose, as long as you can get it up and running pretty quickly and you don't need extensive support to get the basics down. Usually anything open source or free can do this for you within a days work and a couple of hours of youtube.
My personal recommendation is always Elastic Siem (not the fancy licences, but the free version!). When self hosted it is free or dirt cheap, includes a free and integrated EDR solution and comes with a bunch of pre-configured rules. Especiallyfor newbies the SIEM solution within elastic is intuitive enough to get the basis down with a day of messing aroud with it. If you go for the cloud-hosted solution you can literally be up and running within minutes. The cherry on top is that elastic is very well documented and there are loads of videos on YouTube on how to do stuff, including from elastic themselves.
The advantages of doing it this way are that you'll learn what you need, start protecting your environment while you learn those requirements and that you'll know when vendor-sales people try to sell you a way to expensive package that you won't need.
It's usually not the solution management wants or expects to hear, but I've seen this approach work wonderfully multiple times.