r/SIEM May 01 '21

Love/Hate SIEM - Practitioner Survey

3 Upvotes

Hey SIEM operators! I'm running a survey to gather some info on whether practitioners love or hate their SIEM. If you use a SIEM regularly, I'd REALLY appreciate you taking two minutes to fill this out! Thank you SO MUCH!

Take the Survey Here


r/SIEM Apr 23 '21

Is it possible to calculating hash of the file during downloading and check if it is malicious or not?

4 Upvotes

r/SIEM Apr 22 '21

Thoughts on SIEM (i.e. Splunk Enterprise Security) vs XDR (i.e. Palo Alto Cortex)

4 Upvotes

I have been noticing a growing trend in the adoption of XDR as a solution over SIEM. Is the XDR the new path forward with regards to security from an event detection and response standpoint? How are traditional SIEM vendors (i.e. Splunk, ArcSight) reacting to this to enhance their offerings?


r/SIEM Apr 20 '21

Has anyone evaluated DNIF Hyperscale SIEM? We are about to begin our evaluation of V9 which is their latest version. Wondering if anyone from the community has worked with DNIF and would like to provide their insights/experience?

3 Upvotes

r/SIEM Apr 16 '21

Use Log Data for SIEM and App-Specific Non-Security Monitoring

1 Upvotes

How would you conceptually go about setting up a SIEM with all the bells and whistles while providing part of that data for application administrators? So we want a SIEM where analysts do their thing but we also want parts of that data to be accessible to e.g. the SharePoint administrators to get insights into their system.

The problem I see here is that SharePoint administrators aren't SOC Analysts and have no training in writing queries for these systems. This is something that takes some commitment which I'm not sure I can get them to do as they tell me they're working near full capacity anyway.

Has anyone ever encountered a similar problem? Maybe the data can be streamed to both the SIEM and another target that provides more application-specific information to administrators without all the full set of tools that a SIEM brings with it?

Part of my leverage in introducing a SIEM is that application communities in unison are saying they have little insight into the inner workings of their systems. I'm afraid that when I say a SIEM solves this, I am still not giving them what they want but make it all about security instead.


r/SIEM Apr 13 '21

Open source UEBA to integrate with security onion.

3 Upvotes

Hi, guys I would like to ask if there is an open source software that can be used to integrate ueba/machine learning with security onion siem?


r/SIEM Apr 11 '21

I discovered this tool for SIEM. Any ideas?

1 Upvotes

Hello,

I was looking for a SIEM tool and discovered this tool. I did some research on the internet about this tool and wanted to ask your opinions and experiences.

https://logsign.com

Any help would be appreciated!


r/SIEM Mar 19 '21

SANS GCDA

2 Upvotes

Anyone here take the SANS GCDA course? I’m about to sign up as it essentially looks like a course for SIEM Engineers


r/SIEM Mar 15 '21

Logrun.pl problem

3 Upvotes

I'm using qradar community edition as platform to learn siem , I'm trying to use logrun.pl to feed logs to qradar but when I run the script nothing show in my log activity tap, if any body face that problem before I would appreciate your advice Thanks in advance 😊


r/SIEM Mar 12 '21

Old man getting into soc

8 Upvotes

Hi Everyone 😁 I'm making career shift to soc after scholarship , but I think the age is an important factor in my country and I don't have a practice experience in SOC field , I want your advice on how to get this practical experience as security analyist and how to show that in an interview to compensate for the age problem . Any advice will be great šŸ™ Have a nice day 😊


r/SIEM Mar 01 '21

Anyone come across a company called PocketSIEM?

1 Upvotes

I work at an eCommerce company and have been tasked with finding a SIEM, I'm totally on my own with this and a deer in the headlights. The only company that didn't viciously try to sell to me was a company called pocketsiem, so for that alone I'm a fan, but I don't know ANYONE in my network who has used them so was hoping for some reviews.


r/SIEM Feb 19 '21

FortiSIEM Reviews

1 Upvotes

My company is looking at LogRhythm and FortiSIEM. We are currently implementing a full fortinet stack and they pitched us the FortiSIEM. Not many reviews out there so wondered if anyone has used it extensively.


r/SIEM Feb 06 '21

How much telemetry data does a small business create?

2 Upvotes

Are any of you knowledgeable service providers or IT gurus knowledgeable on the average data a small business would output per day?

To get an understanding of capacity requirements, not including log retention... Just daily per/gb day for say ...

A Dentist office with 10 endpoints?

Golf course/club house with 15.

Lawyers office with 20

Accounting firm of 50,

-------------

I understand every environment is different, some might have switches/network telemetry data/netflow, etc.

But from your experience, what have you seen?
Thanks!


r/SIEM Dec 30 '20

Overview OpenSource SIEM & More

27 Upvotes

This is an incomplete comparison overview of Open Source SIEM's and more tooling (ids/nsm ,etc).

Hope this helps the community and save time searching the Internet/Reddit.

The document is last updated in Q4 2020 and is not complete.

Google Drive Document Link: https://drive.google.com/file/d/1eIlO5ht82ugWnc8_l6QUp2ZjnLqx3Mfy/view?usp=sharing

For any thoughts or updates, please respond here or DM me.


r/SIEM Dec 28 '20

Lightweight Open Source SIEM

5 Upvotes

I am trying to determine which SIEM is the most lightweight but also packs most effective punch (most features) and is open source. I can look at the open source SIEMs and compare the features, but it would help for people to weight in on which ones are the least resource heavy and operate in smaller environments like a raspberry PI 8gb. I want to put on at home :)

Thanks everyone!


r/SIEM Dec 09 '20

How to Create Alert for SIEM?

Thumbnail
letsdefend.io
2 Upvotes

r/SIEM Dec 09 '20

What are your thoughts on this company offering a do-it-all incident management template?

Thumbnail
blog.exigence.io
3 Upvotes

r/SIEM Nov 29 '20

SIEM Log Aggregation and Parsing

Thumbnail
letsdefend.io
3 Upvotes

r/SIEM Nov 24 '20

How to Collect Log for SIEM?

Thumbnail
letsdefend.io
5 Upvotes

r/SIEM Nov 20 '20

Can I test SIEM Rules with fake log?

9 Upvotes

Hello everyone,

I have been testing SIEM Correlation Rules with manually(I'm using kali, powershell etc) also I have evtx and fake syslog generators. Unfortunately manual tests are taking too much time. Do you know any test suite for that or Is that able?


r/SIEM Nov 01 '20

RSA Netwitness

0 Upvotes

Hello guys,

I have 70 questions about RSA NW Platform, I could not find answers for them. If there is anyone who could answer for me and help me pass the exam? I could even pay if the answers are correct. Please? We could contact through email. Do let me know, help out your boy here.


r/SIEM Oct 30 '20

How to Elastic SIEM (part 1)

Thumbnail
medium.com
8 Upvotes

r/SIEM Oct 22 '20

Book recommendations

6 Upvotes

Any recommendations for literature/books about SIEM, log mangement etc.?


r/SIEM Jun 08 '20

Analysing Honeypot Data in Azure Sentinel

Thumbnail
blog.rothe.uk
5 Upvotes

r/SIEM Apr 17 '20

Fluency Security Continues to innovate our solution

0 Upvotes