I Sliced My SIEM: Finally Getting Value out of Your SIEM!

No ratings

Presented at BSidesLuxembourg 2018 by

SIEM history is linked to the evolution of the security industry. It has been designed initially to manage NIDS noise and then evolved to a correlation platform where outcomes of penetration test reports can be encoded. A couple of years ago, PCI-DSS and other regulations required "log analysis" to check the compliance box and companies matured in security incident response and forensics. SIEM was the natural answer for those needs. That lead many companies to invest (heavily) into SIEM technologies.Nowadays when you talk to executives about SIEM the most common word used is "disappointment". It represents a lot of money and benefit is very low. This talk is about sharing experienced processes that can help any organization to get value out of the SIEM. It is NOT about new "shiny tools" or "easy tricks" that will increase the bill, but test proofed manageable processes that will help you to get the most out of your SIEM.