• Email
  • Like
  • Save
  • Private Content
  • Embed
 

So You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin

by on Apr 22, 2011

  • 3,176 views

So You Got That SIEM. Now What Do You Do?  Anton Chuvakin, Principal, Security Warrior Consulting (@anton_chuvakin)...

So You Got That SIEM. Now What Do You Do?  Anton Chuvakin, Principal, Security Warrior Consulting (@anton_chuvakin)

Many organization that acquired Security Information and Event Management (SIEM) tools and even simpler log management tools have realized that they are not ready to use many of the advanced correlation features, despite promises that "they are easy to use" and "totally intuitive." 
So, what should you do to achieve success with SIEM? What logs should you collect? Correlate? Review? How do you use log management as a step before SIEM? What process absolutely must be built before SIEM purchase becomes successful?

At this presentation, you will learn from the experience of those who did not have the benefit of learning from other's mistakes. Also, learn a few tips on how to "operationalize" that SIEM purchase you've made. And laugh at some hilarious stories of "SIEM FAIL" of course! As a bonus track, how to revive a FAILED SIEM deployment you inherited at your new job will be discussed.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

Statistics

Likes
2
Downloads
0
Comments
0
Embed Views
0
Views on SlideShare
3,176
Total Views
3,176
Post Comment
Edit your comment

So You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin So You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin Presentation Transcript