ORIGINAL REDDIT POST

SIEM Solution Recommendations

Sec Engineer here looking through SIEM options and a bit overwhelmed any advice for avenues to pursue? Edit: Thank you for all the replies! Adding context since a few of you asked what we're solving for. We're a smaller shop and I'll be the one deploying and…

Original postr/cybersecurity

Sec Engineer here looking through SIEM options and a bit overwhelmed any advice for avenues to pursue? Edit: Thank you for all the replies! Adding context since a few of you asked what we're solving for. We're a smaller shop and I'll be the one deploying and running the SIEM myself, so it needs to be SaaS with low upkeep, hold at least 90 days of searchable logs, and ship working automation playbooks out of the box rather than needing a separate SOAR. Data governance is the real driver, meaning control over where our logs go and how long they live.

Collected discussion

25 comments

u/MinEnergy

man, SIEMs can get wild quick, maybe start by defining your specific use cases first

u/kdc824

This is the way...start with "what is the problem you are trying to solve?". Establish requirements (on prem/cloud/integrated with existing EDR/standalone/etc), identify who is responsible for triage/investigation/response and maintenance of the platform, THEN once you have your requirements set, start researching your options.

u/Puzzleheaded_Art6665OP

Thanks for the response was looking into Sentinel but we are a smaller company so its price point is the issue.

u/Puzzleheaded_Art6665OP

Good advice thank you! Problem is we are lacking perspective on our traffic flows. Looking specifically for cloud-based solution. Trying to get a handle on data governance.

u/Puzzleheaded_Art6665OP

This is exactly how I am feeling lol. We are a smaller company and as far as time concerns we don't have much which has pushed me towards something with an easier setup.

u/bohyler

Yes. We are a Huntress shop and that is our natural SIEM. I would recommend having different layers and vendors in your security stack, but EDR and SIEM being the same makes sense.

u/ngoni

That's a good caveat. If you're primarily monitoring Azure and Windows, then Sentinel will mostly be the easy button. If you stray from Microsoft products, Sentinel can probably still get the job done, but you're in for a bunch of DIY stuff that something like Splunk would be much simpler to get setup. After three years using Sentinel, I can make it do what we need but it's almost never a simple process.

u/stayoutofwatertown

EDR SIEM integration is critical.

u/RobotManYT

I heard firms telling me "ho should really get a siem", but without really explanation to help towards what I should look, i second others by saying define first because log can be intense...and useless when too many. Also depending on the size and the time available of your company there is nice opensource project that you can selfhost (forgot the name of the platform)

u/owl_jesus

Definitely look at your EDR vendor’s solution a lot to gain by having those two paired.

u/Router_RIP

Microsoft shop - go with Microsoft sentinel

u/Every-Earth-1193

Depends on the team's skills and the infrastructure. For example, Splunk wouldn't be optimal if the team is not familiar with data ingestion and SPL. Sentinel would be good if your system runs mostly on Windows and Azure and it's also much easier to use than other SIEMs. You could also get open-source SIEM if cost is an issue but you need to configure it correctly or it could end up being even more expensive.

u/deadpool107

If you use crowdstrike I do enjoy the crowdstrike next-gen SIEM

u/pizzthepizz

I've been working with Splunk for the last two years and I personally find it good. It's been a bit hard to grasp for me at the beginning (specially if you're going to manage all the data ingestion, parsing, indexing and so on) but once I got the hang of it I find it pretty efficient for the tasks I need to do. Please feel free to ask any questions you may need to be answered!

u/Gambitzz

If your a Microsoft shop mostly.. Sentinel.

u/jdiscount

Not enough information to give any help. What's the size of the team, budget, amount of apps / tools being ingested, daily data ingest amount.

u/mattsou812

That's a loaded question without any info to go off of like budget, #of users, log sources you want to ingest, goals, kind of environment, etc. Lots to take into account.

u/Oompa_Loompa_SpecOps

Depends on your use case and the size of your shop and team. It usually makes sense to look into what your EDR already provides as a lot of the event data you want to corellate will be coming from there anyways, so ingesting all of that event data somewhere else might be more costly than vice versa. Crowdstrike NG-SIEM is quite nice, Cortex and Sentinel are usable as well. Elastic is rather powerful (but needs more engineering brains to use properly than for example Crowdstrike) and I'd really like to know the scale that guy who claimed it doesn't scale well operates at, because we have a couple of pB in our cluster and it runs like a charm...

u/Menzoberanz

Smaller company should defenitively take a look at Rapid7 InsightIDR

u/anonps

Go for an AI SOC + MDR service, unless you have a team of engineers / analysts that can deal with customisation. What’s the size of the company? I’m head of sec ops for a 1-2k employee org I can give some pointers if you want to DM.

u/TraditionalBeing2953

CrowdStrike

u/semipvt

Check out Gravwell.io We migrated to that from Splunk due to license costs. We're very happy with that decision.

u/exlabbu

It depends :) If you need to secure small organization i suggest you stick with XDR and SOAR not to go for SIEM. I cant recommend you any opensource SOAR (i know only enterprises solutions) but great XDR/SIEM option is Wazuch. But this is not an option for medium/big company (many "medium" companies in reality are small from security point of view). For larger company you could go for fully SIEM - but is important to know what you looking for - if you have small resources and not so many money do not go for Splunk. Target other solutions - more Out-Of-The-Box like Paloalto XSIEM (already have a mature SOAR on board) or FortiSIEM. I personally like Splunk, but Splunk even with Splunk Security is more like a framework where you need to build that ship of your own before you could sail with it :) But if you are really large organization i think you have security architects to plan your architecture - and probably you would have a few SIEMs (its complicated) i hope that a bit help you with decision :) I only need to annotate that SIEM isn't a better XDR - you should have XDR or really good EDR (in most cases this is XDR) when you have SIEM

u/arloluc

I’ve used ArcSight, QRadar, Splunk, Sentinel and Google SecOps. The biggest challenge in all of them is log onboarding (filtering, transforming, normalising, etc.). I would start by looking at the logs you want to onboard and how they are supported by the SIEM platform out of the box parsers. Like others have mentioned, a good idea is to get an intermediary interface like Cribl. If you go all in with a SIEM’s solution deployment strategy, e.g using Splunk forwarders or Azure Monitoring Agent (AMA) to onboard in Sentinel, you will get locked in with one vendor. Once you want to move to a new solution because the license has become too expensive or simply you want to move a better solution, you will have a very hard time migrating. Having an intermediary like Cribl, will allow you to simply point to the new platform without the need to make changes at the source. Moreover, let’s say your organization is heavy in Cisco devices. The network admins use the SYSLOG stream to send all logs to a repository in case they need to troubleshoot an operations issue in the future. To onboard the firewall logs they will propose to you to use eStreamer format. QRadar and Splunk have built-in capabilities to onboard these logs. For other platforms you need to setup a Linux box in between to process the eStreamer logs using the eNcore client so it can spit out SYSLOG for the SIEM to parse the logs. Cribl supports eStreamer as well. For any SIEM engineering work will be required, specially when it comes to developing automations. You want to spend time developing detection rules and automations; this is where is the value is for these platforms. However, if the logs are not properly onboarded, you won’t be to do any of that. Hence, check which platform offers the best solution to onboard the logs in your organization. All the SIEMs have similar capabilities in terms of detection rules, integrations with third party systems, etc. Having said the above, RunReveal sounds promising. I’ve never used it, but it has built-in capabilities to filter, normalize and transform logs . Moreover, you don’t pay for ingestion, only for retention. All solutions I mentioned at the start you have to pay for both, specially those which are SaaS