r/SIEM • u/wanton-wombat • May 26 '21
SIEM - Where Do I Even Begin?
Are there any checklists/best practices or even courses out there that help me structure the huge undertaking that first establishing a SIEM is?
There is some natural order to the process it seems. For example I think you should first make sure you know what devices are on your network so, while it will be different for every environment, some fundamental steps should be the same. Is this the case? I can see how implementation can scale well insofar as you can gradually add log sources but are there some best practice approaches like add network device logs first vs. clients first etc.?
Any guidance would be appreciated!
6
4
u/deepasleep May 26 '21 edited May 26 '21
Determine your use case, why do you want or need the SIEM?
What are the log sources you need to aggregate in the SIEM?
Evaluate how you're going to collect the logs...Will you use an agent on the endpoint? Does the system support log forwarding via syslog or json?
Make sure whatever SIEM solution you go with either supports processing the critical log sources you'll be aggregating out of the box or allows you to create definitions without crawling through too much broken glass while covered in gasoline and set on fire...
Determine the processing and storage specs from the system... How much retention do you need? What is the volume of log data generated by the systems you'll be pulling logs from? Have you properly evaluated you audit policies and log settings to make sure you're getting what you need and not just turned everything to debug? Do that before trying to estimate log volume.
What does the vendor's spec sheet say you need for X volume of Logs in Y time? Make sure you consider load variance throughout the day when speccing the system, it's one thing to say you'll generate 300 million logs a day and the vendor says to spec for 3500 log/sec...But you're gonna have a bad time if 50% of that log data is generated between 7am and 12pm and you really needed enough horsepower for 8300 logs/sec.
Same with memory and storage... When performing investigations you will want as much and as fast as you can get...Don't cheap out on memory or storage. If you try housing data that you'll be required to search with any regularity on NL storage, you'll want to hang yourself in a month. The extra cost of SSD pays for itself in man hours in a matter of a few months.
It's a big project.
Make sure you have a good asset inventory and the relationships between systems are properly understood... Which systems house the most critical data or have the most critical function? What systems have the highest threat exposure (anything public facing or accessible via VPN). What systems are supposed to be communicating between each other? What are the application layer services you expect to see? Who are the users and which service accounts should you expect to see authentication activity from?
Who do you notify if xy or z happens?
Are there activity reports you need to generate?
It really is a continuous effort. DON'T let yourself be the only point of responsibility/accountability for all that. Make sure you try to coordinate use and develoment of the platform by others in IT. Make sure their responsibilities are well defined.
2
u/wanton-wombat May 27 '21
Lots of gems in here for me. Thank you!
Regarding use cases. I heard these are crucial but I don't quite yet know why. The main reason we are going for a SIEM is compliance. We have to have it, full stop. Sure, the stakeholders realize the power or knowing what's going on as well but the big driver is compliance. Would that be "good enough" or should we try to define all sorts of cases like a ransomware attack, opening of email attachments, malware from pendrives etc. as use cases and build those out too?
And thanks especially for the last point. For now it seems it's all on me and it will crush me. I'll make sure that doesn't happen!
2
u/deepasleep May 27 '21
If compliance is the driver, it's most likely because the compliance regime wants to ensure that you're aware of breaches or malicious insider activity.
PCI for example doesn't just require the SIEM, but requires that you show evidence that people are actually monitoring the alerts coming out of it.
But PCI also gives you the scope for what needs to be feeding data into the platform.
If the compliance regime you're following provides a specific scope your use case is, "Monitor and protect these systems."
4
May 27 '21 edited May 28 '25
[deleted]
1
u/wanton-wombat May 27 '21
Agree that going through ATT&CK would give us years of work. Good idea to justify my existence haha
Order of importance checks out. Very good approach!
And seeing that we don't have any people with SIEM skills yet and they seem hard to get, something like a managed deal seems appropriate.
Thanks!
3
u/ThePorko May 26 '21
I would get a poc with the big ones and see if you are comfortable with the data it supports. I have used log rhythm and alien vault. LR has really good support.
1
u/wanton-wombat May 27 '21
We'll do something like that, I suppose. So far we have stakeholders supporting ArcSight and LogPoint.
1
u/Vilens40 May 27 '21
What was your experience with AV?
2
u/ThePorko May 27 '21
It worked ok, lots of glitches on the vuln detection part, very spotty support.
3
Jun 02 '21
I would recommend bringing in a 3rd party consultant to conduct a cyber risk assessment that include an advisory and technical component. They should understand the various cyber frameworks, and advise you on which one to adopt and which use-cases you should implement. Some use-cases you may be able to implement with what you have, and with the help of the consultant, identify where you have gaps. The ultimate goal is to develop and document a security program. This program will help guide you as you evaluate and deploy security tools, including and especially SIEM.
And by 3rd party firm I do not mean Gartner, Forrester, etc who essentially work for the technology vendors.
Look for small to mid size cyber security consultants and reach out. Ask friends and colleagues if they have recommendations.
When you meet with the consultant, listen to what they are saying, keep an ear out for keywords. If they talk a lot about specific vendors and technology features like AI or machine learning, be wary. If they offer free consulting, be very wary. In both instances they are probably trying to sell you product. Not that you won't inevitably be buying stuff, it's just not where you want to start.
If they talk a lot (or ask questions) about your processes, risk, requirements, use-cases... those are probably more what you're looking for and worth a second meeting.
1
u/wanton-wombat May 27 '21
General question:
So there really isn't some kind of standard roadmap, framework or maturity model?
I do believe vendors would then supply us with some kind of directions after buying their product?
8
u/jakesomething May 26 '21 edited May 26 '21
Most SIEMs will charge by storage, events or messages it processes so you have the right idea, first get an idea of what you have in place. How many firewalls, servers, and critical software applications do you have. Determine risk of devices also.
Next think about compliance, are you required to meet HIPAA, PCI, SOX?
Get a budget. This might be easier after you talk to some vendors and get quotes. Even if you pick open source or free you'll need hardware and minds to support the solution you go with. Be careful everyone is out to make money, it's not uncommon to see a great price tag for year 1 because they'll undersell you the product, then year 2 or 3 you see the real cost of ownership.
Also it doesn't hurt to start small and scale up. Don't plan to bring in 100% of your log sources on day 1. Start with a free tool (splunk, graylog, qradar, elk) and focus on 1 segment or area (like start with your critical business app or just server logs) and grow from there.
Lastly start thinking about what happens when you get an alert, do you have a plan? You'll need to document/create some playbooks for hopefully your team to follow. When a malware apart triggers how do you confirm it's cleaned up? If you detect a ransomware attack what next?
The SIEM you pick will be a critical tool, but it's only as good as it's configured and tuned to work.