Interestingly enough (if I read Google Analytics correctly) the post I created back at the beginning of November related to the question of is ArcSight hard to use was the most visited page over the last month. In fact I think it has been on or towards the top of the list since I posted it. Since I have some time on my hands I figured I would write a sort of follow up to that post. Once again I will state that my only SIEM experience is with ArcSight so maybe someone will speak up for the other SIEM engines out there and/or tell me if I’m way off base.
I still maintain asking if something is “hard”, generally speaking, often only gets you only so far. Having some context implied in your question might get you an answer closer to what you really are looking for. Is calculus hard? Depends on who you are talking to. Is calculus harder than basic algebra? Yup. Is “ArcSight” hard to use? Depends on who you are talking to. Is ArcSight harder to use than some other SIEM? Ahh now we are getting somewhere. I did have sort of an interesting thought while reading the SIEM implementation book I wrote a review of back in January (at least it was interesting to me).
Thursday, March 31, 2011
Monday, March 28, 2011
How to boil the ocean
I did a very (non)scientific experiment this morning with the idea of trying to see the best way to boil the ocean….well ocean by proxy anyway. I took a liter of water and slowly added it a bit at a time to a pan and timed how long it would take to come to a decent boil; was a little over 6 minutes. Cooled the pan down, filled it with another litter of water, set the heat at the same place, and timed it. This time it took just over 8 minutes to get to about the same state.
What’s the point other than having too much time on my hands? Am guessing you might have heard the cliché “don’t try to boil the ocean.” Relative to SIEM stuffs I take a few things away from my little experiment that are all interrelated:
What’s the point other than having too much time on my hands? Am guessing you might have heard the cliché “don’t try to boil the ocean.” Relative to SIEM stuffs I take a few things away from my little experiment that are all interrelated:
Friday, March 11, 2011
SIEM Maintenance Support Costs and Returns
Anton Chuvakin recently wrote up a great blog article discussing SIEM associated costs. While it is my attention to write a longer post here to go a little more in depth on a comment I made in his article I wanted to post something quickly about a line item that probably doesn’t get a whole lot of attention after the bean counters and upper management have done their thing and papers are signed…until something breaks or there is a technical issue of one flavor or another.
Sunday, January 30, 2011
Book Review - Security Information and Event Management (SIEM) Implementation
In short – if you have been “doing” SIEM for any length of time you probably won’t get a whole lot out of this book. Conversely if you are starting to venture down the SIEM path you might want to pick it up.
I first read about this book on Dr. Anton Chuvakin’s blog. Even though his review was less than stellar, he did give it 4 stars (I'd give it 2.5). Similarly although the book’s title includes “implementation” and I have been using ArcSight for a little over two years now so I figured I would give it a shot. I was hopeful…and ended up sort of disappointed. Don’t get me wrong; I appreciate the time and effort the authors put into the book. There really isn’t a whole lot of SIEM type information “out there” which is one of the main reasons I started my own SIEM-esque blog. I think this book has the most value if you haven’t bought a SIEM through 3 or 4 months into your SIEM deployment as a way to level set the conversation (though the first part of the book is very basic).
Saturday, January 8, 2011
ArcSight - The SIEM Lego Set. Take 2
I wanted to post something a little more positive when it comes to the ArcSight Lego concept. Several months ago a group at work was charged with justifying a particular line item of their budget relating to the use of online resources and subscription fees. What they didn’t have was a way to link users to particular site browsing. The issue was bounced around just a bit until it hit my plate and with ArcSight’s feeds the solution was fairly easy to craft (though the devil is in the details). Everyone’s environment is different and different vendors/solutions generate different logs. Again, I don’t have access to other SIEM solutions so not sure how easy or hard coming up with a similar solution would be. While this isn’t specifically a security use case, the concepts or individual elements could be useful for one down the road. I have reused the login tracker a number of times.
Subscribe to:
Posts (Atom)