Cloud Security Podcast by Google

EP228 SIEM in 2025: Still Hard? Reimagining Detection at Cloud Scale and with More Pipelines

27 snips
Jun 2, 2025
Alan Braithwaite, Co-founder and CTO of RunReveal and a passionate data engineer, dives into the challenges of modern Security Information and Event Management (SIEM). He discusses the complexities of storage and integration in SIEM systems while comparing decoupled architectures with integrated solutions. With data volumes surging, Braithwaite envisions using ClickHouse for efficient log management. He also introduces 'Pipeline QL' for detection in SQL, sparking debates about its implications for security engineering and interoperability in the ever-evolving landscape of security data.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Modern SIEM Leverages Big Data

  • Leveraging modern big data tools like ClickHouse modernizes SIEM architecture effectively.
  • Focus on built-in detection features first accelerates usability and analytics capabilities.
INSIGHT

SIEM Architecture Debate Is Moot

  • The SIEM debate between decoupled storage and integrated solutions is largely moot.
  • Users want flexibility to extend and use security data beyond detection and response alone.
INSIGHT

Cost Control via OLAP Compression

  • Cost control in SIEM is essential to compete with established vendors like Splunk.
  • High compression OLAP tools like ClickHouse reduce storage cost and improve performance.
Get the Snipd Podcast app to discover more snips from this episode
Get the app