Navigated to EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

November 3
29 mins

View Transcript

Episode Description

Guest:

Topics:

  • Are we really coming  to "access to security data" and away from "centralizing the data"?
  • How to detect without the same storage for all logs?
  • Is data pipeline a part of SIEM or is it standalone? Will this just collapse into SIEM soon?
  • Tell us about the issues with log pipelines in the past?
  • What about enrichment? Why do it in a pipeline, and not in a SIEM?
  • We are unable to share enough practices between security teams. How are we fixing it? Is pipelines part of the answer?
  • Do you have a piece of advice for people who want to do more than save on their SIEM costs?

Resources:

See all episodes

Never lose your place, on any device

Create a free account to sync, back up, and get personal recommendations.