• Email
  • Favorite
  • Download
  • Embed
  • Private Content

Loading…

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

Got SIEM? Now what? Getting SIEM Work For You

by Anton Chuvakin on Nov 11, 2010

  • 2,153 views

Got SIEM? Now what? Making SIEM work for you!...

Got SIEM? Now what? Making SIEM work for you!

Dr Anton Chuvakin
SANS 2010

Security Information and Event Management (SIEM) as well as log management tools have become more common across large organizations in recent years. SIEM and log management have also been a topic of hot debates. In fact, you organization might have purchased these tools already. However, many who acquired SIEM tools have realized that they are not ready to use many of the advanced correlation features, despite promises that "they are easy to use." So, what should you do to achieve success with SIEM? What logs should you collect? Correlate? Review? How do you use log management as a step before SIEM? What process absolutely must be built before SIEM purchase becomes successful. Attend this session to learn from the experience of those who did not have the benefit of learning from other's mistakes. Also, learn a few tips on how to "operationalize" that SIEM purchase you've made.

Accessibility

Categories

Tags

worst practices chuvakin best practices log management siem sem sim log mgmt

More...

Upload Details

Uploaded via SlideShare as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

Statistics

Favorites
2
Downloads
0
Comments
0
Embed Views
0
Views on SlideShare
2,153
Total Views
2,153
Post Comment
Edit your comment Cancel

Got SIEM? Now what? Getting SIEM Work For You — Presentation Transcript