

EP228 SIEM in 2025: Still Hard? Reimagining Detection at Cloud Scale and with More Pipelines
27 snips Jun 2, 2025
Alan Braithwaite, Co-founder and CTO of RunReveal and a passionate data engineer, dives into the challenges of modern Security Information and Event Management (SIEM). He discusses the complexities of storage and integration in SIEM systems while comparing decoupled architectures with integrated solutions. With data volumes surging, Braithwaite envisions using ClickHouse for efficient log management. He also introduces 'Pipeline QL' for detection in SQL, sparking debates about its implications for security engineering and interoperability in the ever-evolving landscape of security data.
AI Snips
Chapters
Books
Transcript
Episode notes
Modern SIEM Leverages Big Data
- Leveraging modern big data tools like ClickHouse modernizes SIEM architecture effectively.
- Focus on built-in detection features first accelerates usability and analytics capabilities.
SIEM Architecture Debate Is Moot
- The SIEM debate between decoupled storage and integrated solutions is largely moot.
- Users want flexibility to extend and use security data beyond detection and response alone.
Cost Control via OLAP Compression
- Cost control in SIEM is essential to compete with established vendors like Splunk.
- High compression OLAP tools like ClickHouse reduce storage cost and improve performance.