SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • May 31, 2023
  • Rss Fetcher
Eric Thomas
Contributor

Share on Twitter

Eric Thomas is vice president of security GTM at Logz.io, an open-source observability platform for DevOps teams.

Security information and event management (SIEM) is one of the most well-established categories of security software, having first been introduced about 20 years ago. Nevertheless, very little has been written about SIEM vendor evaluation and management.

To fill that gap, here are six top-line tips on procuring and implementing a SIEM solution for maximum value.

Evaluating and purchasing a SIEM solution

Size your spend

SIEM software solutions are priced differently: either by the number of employees in the customer organization, by the rate of events per second, or based on the log volume ingested. It’s important to figure this out early to get a rough idea of what you will pay over time. You’ll also identify the various data sources meaningful to your Security Operations Center (SOC).

Buying a SIEM is a massive commitment: you and your organization will need to live with your decision for years to come.

If you already have a SIEM in place, give the vendor your current use cases and consumption, and they should be able to replicate it. If you don’t, you’ll need to do a little leg work. A good starting point is assessing the volume of logs you’ll send to the SIEM. Measure actual daily log volume from each source by checking out the locally stored logs for a “normal” day and tallying the results.

If the SIEM vendor charges by your number of employees, be wary. This is usually a way to charge more for the SIEM by counting employees who don’t generate any relevant data.

Evaluate your vendor’s practices

The next step is to conduct a proof-of-concept (POC); this should be a starting point for an eventual implementation, not a standalone, canned exercise. During this process, your vendor should demonstrate a service level that you’ll want to maintain post-sale. Here are some key questions to consider during this process:

  • Who will staff your account? Ideally, a vendor will commit skilled technical staff to both execute your initial evaluation and conduct an implementation.
  • Who from your team will take the technical lead on the evaluation, and who’ll ultimately implement it? Ideally this will be the same person or small group of people.
  • After you buy a SIEM, what’s next on your roadmap? SOAR? CSPM? Make sure your vendor can integrate with a broad range of technologies.
  • It’s critical to fully understand the vendor’s front- and backend software architecture. Some vendors calling themselves “true SaaS” or “cloud-native” are not. Don’t lock yourself into a 12-month contract when you don’t know what’s going on under the hood.

Don’t be fooled: Know the total cost of implementation

Six tips for getting the most out of your SIEM investment by Walter Thompson originally published on TechCrunch

Previous Post
Next Post

Recent Posts

  • US imposes new rules to curb semiconductor design software sales to China
  • Grocery platform Misfits Market acquires The Rounds to further its mission of reducing food waste
  • SEC drops Binance lawsuit in yet another gift to crypto
  • G2 Speech Launches AI Digital Assistant
  • Google fixes bug that led AI Overviews to say it’s now 2024

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.