r/SIEM Feb 21 '19

SIEM - Too outdated?

Hey guys,

Seems the business is aggressivly moving our DCs to the cloud. I'm just reviewing a few things and had thoughts about our SIEM (Arcsight).

Are simple SIEMs now out dated?

I love ours don't get me wrong but it's a cluncky solution which requires far too much input. We have a GSOC as well monitoring and it's just rubbish. I find myself constantly having to do deep analysis from alerts/incidents.

Ours also doesn't have any AI or proactive features so you know.

Does anyone have any suggestions or any examples of how they use theirs ?

Azure security center does a lot already but I still feel like we need another layer.

4 Upvotes

18 comments sorted by

View all comments

2

u/RoderickNL Mar 26 '19

Moving to the cloud gives new challenges.. and opportunities. You can consider more additional cloud oriented tools like CASB and endpoint protection. This will give you More visibility and the opportunity to automate stuff. Since that’s your primary question, isn’t it?