Anton Chuvakin
76p537 comments posted · 4 followers · following 0
5 weeks ago @ Anton Chuvakin Blog - Log Management SIEM = ? · 0 replies · +1 points
Please talk to the vendor :-)
8 weeks ago @ Anton Chuvakin Blog - UPDATED Free Log Manag... · 0 replies · +1 points
18 weeks ago @ Secure Cloud Review - SIEM M&A, MSSP and the... · 1 reply · +1 points
21 weeks ago @ Anton Chuvakin Blog - Top 10 Criteria for a ... · 0 replies · +1 points
RT alerting on known threats (via correlation, or simply filtering "right" alerts from IDS, etc) is definitely within its mission, but it is not its entire mission. Investigative use and other data exploration are successfully done with many SIEM tools (those with not-too-slow backends....)
On the other hand, I am TOTALLY with you on the stored data analysis (e.g. see this www.slideshare.net/anton_chuvakin/log-mining-beyo... where I applied data mining to SIEM data a few years ago); I really want to see more big-data/analytics approaches to SIEM ASAP.
22 weeks ago @ Anton Chuvakin Blog - Got A Pile of Logs fro... · 0 replies · +1 points
In splunk you can just search with no "log support", but often I wanted a nice aggregated summary thus the above comment
22 weeks ago @ Anton Chuvakin Blog - Got A Pile of Logs fro... · 2 replies · +1 points
23 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points
23 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points
26 weeks ago @ Anton Chuvakin Blog - The Last Blog Post! · 0 replies · +1 points
26 weeks ago @ Anton Chuvakin Blog - PCI DSS in Cloud Compu... · 0 replies · +1 points
Joint