当前位置:首页 > 报告详情

简化的SIEM迁移和日常成本优化(Joe Cicero 和 Mike Pinch).pdf

上传人: a****d 编号:402814 2025-01-10 30页 1.80MB

1、Streamlined SIEM Migration and Daily Cost OptimizationJoe Cicero and Mike PinchAgendaIntroductionsJoe CiceroDirector of Strategic AlliancesSecurity Risk Advisors Joe.Cicerosra.io Mike Pinch Chief Technology OfficerSecurity Risk Advisors Mike.Pinchsra.ioThe Problem we all faceWhat to collect,where to

2、 route,and what to do with it all while controlling costsDeconstructing a SIEMStuck in a legacy modelTransition to Data Centric DesignToo many logs,too many sources,too much data Whats really necessary?Capacity and Cost Events per second(EPS)vs consumption(GB/day).SpeedSIEM fallacy give me all your

3、dataWhat could we do differently?Enter the data lakeUnderstanding Your Data SourcesWhere and what logsSecurity Data PipelineA critical feature of a modern SOC operationChanneling your data and taking full advantage of dynamically being able to transform,enrich,reduce,mask,and monitor your log data a

4、llows for little waste or duplication and more visibility into your environment Enhances your agility to migrate tools and platforms by reducing the switching cost and complexity Allows for managing data storage tiering,and only sending logs to your SIEM that are needed for detectionsPut investigati

5、on and compliance logs into a lower cost,hot searchable solution Security Risk Advisors Intl,LLC.Proprietary and Client Confidential11Security Data Pipeline ManagementOur industrys standard approach with SIEMs has been“log everything”Over the years this has resulted in significant increases in log v

6、olumeThe shift to cloud-based SIEMs resulted in consumption-based pricing;the more you use,the more you paySIEM vendors capitalize on the“log everything”approachLog volume has explodedSIEMs are expensive(8-10 x)per GB when compared to a data lakeNot all logs are created equalA log can be an alert on

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了SIEM迁移和日常成本优化的主题。文章指出,我们在处理日志数据时面临的问题包括:收集哪些数据、数据流向何处以及如何处理,同时还要控制成本。传统的SIEM模型已无法适应大量日志、多个数据源和爆炸性数据增长的需求。因此,提出了转向以数据为中心的设计,并引入数据湖的概念。数据湖可以更好地管理和分析日志数据,提高数据处理效率,降低成本。文章还以Cribl和Microsoft Azure ADX为例,说明了数据湖在实际应用中的优势,如减少日志数据量、降低存储成本、提高检测能力等。最后,文章强调了SIEM中安全自动化的重要性,并提供了相关的解决方案。
"如何通过数据湖优化SIEM迁移和日常成本?" "SIEM传统日志路由与现代安全数据管道的区别是什么?" "如何利用Cribl和Azure ADX实现日志收集和分析的革新?"
客服
商务合作
小程序
服务号
折叠