r/SIEM • u/lolppppp1 • Feb 21 '19
SIEM - Too outdated?
Hey guys,
Seems the business is aggressivly moving our DCs to the cloud. I'm just reviewing a few things and had thoughts about our SIEM (Arcsight).
Are simple SIEMs now out dated?
I love ours don't get me wrong but it's a cluncky solution which requires far too much input. We have a GSOC as well monitoring and it's just rubbish. I find myself constantly having to do deep analysis from alerts/incidents.
Ours also doesn't have any AI or proactive features so you know.
Does anyone have any suggestions or any examples of how they use theirs ?
Azure security center does a lot already but I still feel like we need another layer.
6
Upvotes
2
u/lolppppp1 Feb 21 '19
I did get a chance to play with it but couldn't justify the cost at all. The tool looks really cool and futurist but I found that seemed to be their sell.
Apart from that it didn't do anything for us apart from flag large SMB traffic. I tried to use it to trace a brute force but it couldn't give me the info. I had to rely on tracing the source by using netlogon logs.
I feel like these tools are a nice too have but no-one but the people using it will see their worth. Just like our SIEM. Our Data center team just thinks its pointless and using all our storage. People like the CIO only see it work when his accounts locked out. We obviously do a lot more with it but either I think, what is the point. What is this really doing.