Hi dear professionals,
Can you share with the community 2-3 top pain points you've been experiencing during the Security Information and Event Management (SIEM) solution purchase?
How have you been able to overcome them, if at all?
Thanks for sharing your knowledge with other peers.
You’ve got some pretty good answers so far. Here are a few of the pain points I’ve experienced.
I’ve led the purchase of three enterprise SIEMs at two different enterprise organizations and they were all very unique in their challenges. Take your time doing your due diligence and plan as much as possible ahead of time. Don’t get enamored by the sales jargon and really press the vendors on your needs and concerns. Get your needs addressed early in the negotiation process and do your best to cover all your requirements before you sign a purchase agreement. It can be a pricey mistake to underestimate your needs. Be vigilant about what the on-prem server footprint will be as that is the cost that is not part of your contract price (compute cost). Moving from one SIEM to another is both costly and difficult so be sure the SIEM you purchase will be able to grow with your org as its use cases grow.
We've worked in SOC for many years. Here are a few pain points in SIEM solution purchases.
1. License models are not communicated transparently which makes planning complicated. You have to talk to multiple people at multiple vendors in several meetings to fully understand the cost scaling factors. That is quite time-consuming. You can overcome this when you just dictate price limits - yes you can actually do that.
2. Planning and conducting a PoC can be a challenge. Depending on how a PoC process is being setup by the vendor. You can overcome this if you ask for the PoC Procedure Plan right from the initial contact with the vendor and use it for internal planning.
Volume versus costs.
Using an intermediate (free) tool to store, transform data and forward only the sumarization (smartdata) of what really matters.