Can You Roll Your Own SIEM
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the feasibility and benefits of building a custom cloud-native Security Information and Event Management (SIEM) system in this 29-minute Black Hat conference talk. Learn about Two Sigma's journey to replace their expensive third-party SIEM solution, including considerations for threat modeling, feature parity, and data ingestion methods. Discover the operational wins, lessons learned, and cost savings achieved through this in-house approach. Gain insights into the overall effort required, resulting capabilities, and improved observability and flexibility of a custom SIEM solution.
Syllabus
Introduction
Considerations & Requirements
Threat Model
Build vs. Buy
Feature Parity
What We Needed
Batch Loads
Streaming Ingest
Scheduled Queries
Streaming Alerting
Data Access Controls
Operational Wins
Lessons Learned
Overall Effort
Resultant Capabilities
Cost Savings
Observability & Flexibility
Taught by
Black Hat
Related Courses
Введение в теорию кибернетических системSaint Petersburg State University via Coursera Dynamical System and Control
Indian Institute of Technology Roorkee via Swayam Kyma – A Flexible Way to Connect and Extend Applications
SAP Learning Linear Systems Theory
Indian Institute of Technology Madras via Swayam Introduction to DevOps and Site Reliability Engineering
Linux Foundation via edX