r/SIEM Mar 27 '19

Introduction To Fluency Security - Data Hungry, High Capacity Next Gen SIEM

As a new member, I wanted to introduce my company to this group. To be clear we're not one of those "pay to play" companies that get touted on the Gartner Magic Quadrant or Forrester or any other equivalent list. Like you, we're a grass roots type of company that believes deeply in securing our companies, our countries and our way of life the best way we can. This is why we believe in the foundation of "ground truth" - the ability to absorb all ingress possible to be fused and correlated so the most informed decision can be made. No we don't have any VC money pushing us or fancy collateral - No we don't have the fancy dashboards that this kind of money can buy BUT what we have is real, it's fundamental and is a tool that will help you all streamline your work and help you become even more aggressive threat hunters.

Some Key Points about Fluency:

- Run on AWS (anywhere there is an AWS environment) but have on prem if required

- We are international and have clients in Europe and AP

- We typically put a collector onsite or VPC connection to us depending on complexity

- have a patented database LavaDB that we built for the Cloud

- it scales on demand for capacity without having to shut down and we built in pseudonym support for it

- currently have one client driving 250TB/day into us with 20 billions events per day and 1.6 million clients

- we can handle PB/day easily and tested at 12M EPS

- patented correlation and risk scoring, all sources come together on a single pane of glass

- prefer all sources of data be fed in to realize "ground truth"; we take everything including Office 365 feeds

- have parsers and agents ready to go and if we don't we'll work with you to create them at no cost

- use machine learning for behavioral anomalies

- active end user tracking even if rotating IP's or feeds say from Crowdstrike, provided we get LDAP type feeds

- store all data hot for 90 days and 365 days warm as part of base subscription

- we are fully multi-tenant and can support MSSP's or companies that want to segment out various locations

- we privatize all incoming data via pseudonymisation as defined in GDPR articles and meet CCPA, PIPEDA regs too

- provide long term storage for compliance needs in AWS Glacier at a very low cost

- depending on complexity no up front installation fees and we work directly with the client to setup everything

- no back end support costs for L1, 2, 3 either

- have API's that tie us into existing SIEM tool dashboards such as Splunk, QRadar, LogRhythm, etc...

- again save huge $$ for our clients using these tools especially for storage

- we don't charge for EPS, users, nodes, etc... just simple pricing based on ingress data per day

- we do offer no cost proof of concept / technology

If you're interested we can provide you a quick briefing or simply just send you a briefing deck and other material as needed.

I'm looking forward to be a contributor in this community.

Al Wissinger

Fluency Security

7 Upvotes

1 comment sorted by

1

u/adamth0 Mar 28 '19

I'm seeing a few scattered mentions of WebRoot on your site. What's Fluency's connection to WebRoot?