Badges
20 Points
6 Years
User Activity
Over 4 years ago
Answered a question: Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
Neither, or both.
Having done literally thousands of SIEM deployments, I can tell you from experience that the technology choice isn't the most important choice. The critical choice is in the resources and commitment to manage and use the system. I've seen countless SIEM…
Over 4 years ago
Answered a question: What is the difference between IT event correlation and aggregation?
Event correlation is an analytical process that looks for trends, patterns, thresholds, or sequences of events in your data. Even when they may not be the same event type (ex: a VPN authentication event followed by a door badge access event in a different location). There…
Over 4 years ago
Answered a question: Are you using a SIEM platform with AWS Cloudwatch?
CloudWatch is great, but it's not enough on its own. CloudWatch provides some limited alerting capabilities, but this is nothing like a true correlation engine or behavioral anomaly detection engine. You really need to feed your CloudWatch data into a SIEM or UEBA to get…
Over 4 years ago
Answered a question: How can Cloudtrail logs be used effectively to improve log monitoring?
CloudTrail logs are an excellent and necessary way to monitor activity in your AWS environment. They are the "under-the-hood" audit logs much like
OS audit data, but covering the entire cloud infrastructure. This could include things like new compute instances created…
About 6 years ago
Contributed a review of USM Anywhere: The bundle of features is the killer feature, but search performance and Raw Logs are slow
About 6 years ago
Contributed a review of USM Anywhere: The bundle of features is the killer feature, but search performance and Raw Logs are slow
About 6 years ago
Contributed a review of USM Anywhere: The bundle of features is the killer feature, but search performance and Raw Logs are slow
Reviews
About 6 years ago
USM Anywhere
About 6 years ago
USM Anywhere
About 6 years ago
USM Anywhere
Answers
Over 4 years ago
Security Information and Event Management (SIEM)
Over 4 years ago
Event Monitoring
Over 4 years ago
Security Information and Event Management (SIEM)
Over 4 years ago
Log Management