Go jump in a lake: Measuring the data lake effect on your SIEM

Source: Red Canary

Author: Brian Davis

URL: https://redcanary.com/blog/security-operations/data-lake-siem/

ONE SENTENCE SUMMARY:

SIEMs centralize IT data for analysis but can be costly, while data lakes offer a cheaper, scalable alternative.

MAIN POINTS:

  1. SIEMs collect logs from all devices to centralize event monitoring and analysis.
  2. Centralizing logs simplifies identifying suspicious activities across diverse IT environments.
  3. Expanding data sources improves SIEM effectiveness but increases complexity and costs.
  4. Decentralized IT and cloud services expand attack surfaces, requiring comprehensive monitoring.
  5. SIEMs’ cost is driven by data ingestion, storage requirements, and complex infrastructure.
  6. OpenSearch highlights how storage and compute contribute to SIEM costs.
  7. Data lakes use object storage to significantly reduce storage costs compared to SIEMs.
  8. Serverless computing in data lakes offers scalable, cost-effective compute solutions.
  9. SIEMs remain necessary despite cost challenges, but data lakes provide budget-friendly alternatives.
  10. Understanding SIEM and data lake architecture helps optimize IT security budgets.

TAKEAWAYS:

  1. SIEMs centralize logs for improved security visibility but can be expensive due to data processing demands.
  2. Data lakes leverage object storage and serverless computing to lower costs.
  3. Expanding attack surfaces necessitate comprehensive solutions beyond traditional SIEMs.
  4. Efficient IT budget management requires balancing SIEM use with data lake advantages.
  5. Future savings in IT security involve adopting scalable, cost-effective technologies like data lakes.