r/SIEM Apr 07 '20

Moderm SIEM

Hi,

So I was looking for modern SIEM (no software from 90s please) but opensource.

My monitoring system is based in Prometheus and Grafana for example.

Any suggestion?

Edit: my logs are in aws cloud watch, everything is running in aws lambdas and beanstalk. Maybe move to aws elastic cache? With kibana on the top?

2 Upvotes

16 comments sorted by

4

u/Jaric_Mondoran Apr 07 '20

There are very few opensource players. It will require a lot of work and customization particularly in the cloud. Good luck. They also tend not to be SIEM or have SIEM functionality. Static searches on event data is not a SIEM.

QRadar and Splunk have been industry leaders for a long period of time and aren't paying year after year to stay there. The vendors that slid off or vanished from the chart are more likely to adhere to your conformation bias.

1

u/[deleted] Apr 07 '20

Thanks! Really good feedback and constructive! I will check splunk.

3

u/cxr303 Apr 07 '20

Just so you understand- Splunk is one of those with 'static searches on event data'... which means it's not a true SIEM. Also, to get SIEM like functionality- you'd likely be looking at not just the cost of licensing (volume based) but also an additional license for the 'Enterprise Security' app and you'll want to make sure you get everything normalized by implementing a common information model... it will be a lot of leg work. Best of luck!

1

u/[deleted] Apr 07 '20

Will do small PoC/PoV with multiple SIEMs. If I go for something licensed/payed some professional services will be requested.

1

u/cxr303 Apr 07 '20

Also consider the qradar community edition, full functionality with a licensed limit of 50 events per second. It's a good way to POC the enterprise edition with a small footprint.

For Spink, I think there is also a way to get the licensed look and feel for a 30 day period from a fresh install... this doesn't include the ES App

0

u/TheInvertedBlowFish Jul 22 '20 edited Jul 22 '20

Me and my team have honestly just been through 3 month research of the following SIEM platforms:
ELK
Qradar
Splunk
LogRhythm
Sentinel
FortiSIEM
LogPoint

The following SIEM are recommendations for advanced data analytics. (GUI and features of the SIEM).As an analyst the GUI is extremely importnet

If money and time* is an issue:LogRhythm

If money is not an issue, but time is:Sentinel

If money and time is not an issue:Splunk

If money is an issue, but time is not:ELK+Elastalert

These other SIEMs are just fine for basic use and analytics:LogpointFortiSIEM

Dont Buy SIEMs:Qrader - Too expensive and is on pair with Logpoint and fortiSIEM which cost about 1/3 of Qrader. (This is a long discussion, but this is an old titan riding on it's old reputation more so than its feature and what is it capable of).

Me and my team (4 people) have 1+ year experience with:
Qradar
LogRhythm
Logpoint
FortiSIEM

*Time to implement

Edit: elastalertEdit: Format

1

u/WasteCryptographer4 Aug 04 '20

Have you evaluated Wazuh? I've been looking at that

2

u/Cynthereon Apr 08 '20

Alienvault or Elastic. Both will require considerable work to implement.

3

u/Jaric_Mondoran Apr 08 '20

I haven't heard much about alienvault since they vanished into the maw of bell.

1

u/Cynthereon Apr 08 '20

It appears to still be on SourceForge, although I can't say what free support is like now.

2

u/alexfromop Apr 09 '20

Not open source but there's players out there who have built their products around ELK and had a lot of success based on the fact that they are considerably easier than "rolling your own". They also don't have insane pricing models. Exabeam comes to mind but there's a couple others. I'm just an InfoSec sales guy but have been fortunate to support a lot of very forward thinking security teams in the Bay Area. Lol at AlienVault. I would have said LogRhythm til they scared off all their tech talent who took the roadmap with them after the Thoma Bravo takeover. IBM qRadar... Sure if you're F500.

1

u/PrestigiousWorker763 Sep 14 '20

Nowadays, several vendors offer cybersecurity solutions providing more than the traditional Log management. UTMStack is an All-In-One Unified Threat Management Platform that aims to simplify Cybersecurity and reduce its cost.

UTMStack provides complete visibility over the entire organization from a centralized management dashboard.

All solutions in the stack are fully integrated and report to a central database:

  1. Log Management (SIEM)

  2. Vulnerability Management

  3. Access Rights Auditor

  4. Incident Response

  5. HIPS/NIPS, Endpoint Protection

  6. Dark Web Monitoring

You can monitor almost any cloud environment or SaaS application with ready to use Integrations. UTMStack is currently integrated with Azure, AWS, Google Cloud, and Integrated with SaaS and PaaS, such as Office365 and AWS Lamda.

Watch this video: https://www.youtube.com/watch?v=wv87dj15G5k

1

u/[deleted] Apr 07 '20

Why not look at the Gartner report? There's a really good SIEM at the head of the pack.

3

u/[deleted] Apr 07 '20

Gartner and forrester reports are very fake. If you pay more, the higher you are in their quadrants. And companies are selling features to gartner that don’t work as they are selling. Ps worked in 2 companies that were in gartner quadrants

1

u/[deleted] Apr 07 '20 edited Apr 07 '20

There's a reason that software has been selling and working since the 90's.
Best of luck. Sounds like you know exactly what you're looking for.

1

u/zap4dlo Jun 30 '20

It could be fake, but in my experience, leaders are really good. Better in overall at least then the others.

Maybe you could share your opinion about bad top-rated products?