When Erich Winkler explained Security Information and Event Management (SIEM), he started by talking about events.
“On a medium-sized corporate network, we are talking about tens of thousands of log entries every single minute. Hundreds of thousands per hour. Millions per day.”
A lot of events, and a lot of information. Now here is the problem.
“Now imagine your job is to find the three events in that ocean of data that actually indicate a real attack.”
Ouch. But that’s why we need tools, friends.
To find out why you need to tune your SIEM tool to reduce false positives without hiding real ones, read Decoded Security.
