About 2 months ago
Replied to Seckin Demir The Math of SIEM Comparison
@Seckin Demir If my comments do not satisfy you about the McAfee SIEM, you can check comments from Gartner. Limited advanced features and add-ons: McAfee lags behind competing SIEM vendors that offer cloud-native SIEM options, ML powered UEBA and SOAR add-on…
3 months ago
@reviewer1469436 Some SIEMs keeps data(log) hot for a long time with minimal disk size. For example, for 10000 EPS and 365 days live (hot), they require 20 TB disk size.This model may be easier than your model and very fast.
3 months ago
Some examples https://drertugrulakbas.medium...
5 months ago
Replied to Gary Budnick The Math of SIEM Comparison
@Gary Budnick, I think it is not missing. I mentioned their UEBA capability in my article.
5 months ago
Replied to Augusto Barros The Math of SIEM Comparison
@Augusto Barros my sentence is: "Exabeam and Securonix are UEBA tools. They are not correlation-based solutions". It does not mean that Exabeam and Securonix do not provide the ability to build correlation based rules. I tried to emphasize their UEBA capability.
5 months ago
@CraigHeartwell, ​thanks for your spelling correction.  ArcSight acquired Interset for ML. Yes, LogRhythm can handle the logic. SIEM Comparison table is on my mind for a long time. I published the Turkish version. I need to work to extend it before publishing.
6 months ago
They are not same. For evet monitoring (log management) aggregation is enough but if you need correlation then SIEM required. Aggregation  means log parsing and correlation means developing rules to detect attacks
7 months ago
@John Stanford, you are right. A good Security Platform includes SIEM, UEBA, NTA, and SOAR. But most of the time, you have a limited budget, and you should select the best solution according to your budget. Especially for small businesses, budget is critical. If there is no…
7 months ago
@Mike Kehoe There is no technical solution that does not require maintenance. You can outsource it or use a cloud-based solution. If you use a cloud-based solution, you have to check issues like compliance, regulations and ownership of the logs.

Specialties:SIEM/NMS/Log Management/APM, understanding the security data,