Anton Chuvakin

Anton Chuvakin

76p

537 comments posted · 4 followers · following 0

5 weeks ago @ Anton Chuvakin Blog - Log Management SIEM = ? · 0 replies · +1 points

>please assist

Please talk to the vendor :-)

8 weeks ago @ Anton Chuvakin Blog - UPDATED Free Log Manag... · 0 replies · +1 points

Scribe (and flume) is smth I wanted to test first before adding to the list; but now I am too busy to do that, sorry!

18 weeks ago @ Secure Cloud Review - SIEM M&A, MSSP and the... · 1 reply · +1 points

What's up with misspelling SIEM as "SEIM"?

21 weeks ago @ Anton Chuvakin Blog - Top 10 Criteria for a ... · 0 replies · +1 points

Thanks for the comment. Unfortunately, such view of SIEM as "a meta-IDS" is extremely shortsighted. SIEM is neither a better IDS, nor meta-IDS.

RT alerting on known threats (via correlation, or simply filtering "right" alerts from IDS, etc) is definitely within its mission, but it is not its entire mission. Investigative use and other data exploration are successfully done with many SIEM tools (those with not-too-slow backends....)

On the other hand, I am TOTALLY with you on the stored data analysis (e.g. see this www.slideshare.net/anton_chuvakin/log-mining-beyo... where I applied data mining to SIEM data a few years ago); I really want to see more big-data/analytics approaches to SIEM ASAP.

22 weeks ago @ Anton Chuvakin Blog - Got A Pile of Logs fro... · 0 replies · +1 points

Well, a commercial SIEM will have hundreds of supported log types, but at cost of $$

In splunk you can just search with no "log support", but often I wanted a nice aggregated summary thus the above comment

22 weeks ago @ Anton Chuvakin Blog - Got A Pile of Logs fro... · 2 replies · +1 points

Indeed, splunk would be my #1 choice for searching and I will do some exploration there as well, but having a need to summarize logs that splunk might not support comes pretty often in such circumstances... e.g. no N=V pairs, not nicely structured logs, etc.

23 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points

Thanks a lot! Regarding Stamford, I was there last week :-( No immediate plans to go back, but it might well happen.

23 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points

Well, not to worry: blogs.gartner.com/anton-chuvakin

26 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points

Thanks!!

26 weeks ago @ Anton Chuvakin Blog - PCI DSS in Cloud Compu... · 0 replies · +1 points

It might be offered again in the future, but I have no additional info at this stage