
EP228 SIEM in 2025: Still Hard? Reimagining Detection at Cloud Scale and with More Pipelines
Cloud Security Podcast by Google
00:00
Rethinking Detection: SQL vs. Sigma
This chapter explores the limitations of SQL in security detection, particularly through the lens of PipelineQL (PQL), and contrasts it with more effective alternatives like Sigma. The discussion highlights the need for intuitive languages that enhance real-time alerting and better serve security engineering roles.
Transcript
Play full episode