
SIEM and SOAR, and who is watching
A SIEM collects the logs of everything running and looks for patterns in them. That is useful as soon as somebody looks at the outcome, and expensive log storage as soon as nobody does. This page is about that second half, because that is where it stalls in practice.
Three layers, in this order
They are sold as one package and are three separate decisions.
- CollectingLogs from workstations, servers, firewalls and cloud services in one place, kept long enough to look back. This alone is value: after an incident you want to know what happened, and that is usually when the logs have just rolled over.
- RecognisingRules and patterns that pick out a suspicious sequence: a sign-in from another country, an account suddenly opening a thousand files. This is the part that mostly produces false alerts in the first months and has to be tuned.
- RespondingSOAR: recorded steps that run automatically on a known alert, blocking an account, cutting a device off the network. Only worthwhile once the recognition is reliable, and not before.
Three things that must be clear beforehand
This is the dearest security measure per euro, and the most useful when it fits.
- Somebody has to be watchingAlerts nobody assesses are not security. Expect an agreement on who watches, within what time, and what happens outside office hours. That is a service and not a setting.
- The bill grows with the volumeThe price depends on how much is sent in. So choose which sources go in rather than all of them, because all of them is expensive and produces more noise besides.
- It often arrives too earlyWithout two-step verification, without patched systems and without a backup that has been restored, a SIEM is the dearest answer to the wrong question. Do the cheap things first.
What belongs with this
Detection sits on top of the basics and not in front of them.
Find out whether this is next
Tell us what security is already in place. You get an honest answer on whether a SIEM delivers now or whether something else has to come first.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.