Cloud Security Podcast by Google

EP197 SIEM (Decoupled or Not), and Security Data Lakes: A Google SecOps Perspective

31 snips
Nov 4, 2024
Travis Lanham, Uber Tech Lead for Security Operations Engineering at Google Cloud, dives deep into the future of SIEM-like products. He discusses the concept of disassembled SIEMs and their potential advantages, like separating security capabilities from data backends. Lanham reflects on the early days of SecOps and shares why a tightly coupled approach was preferred. He examines the complexities of decentralized systems and their implications. The conversation also touches on innovations driving decoupled SIEMs and insights into security data lakes.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

SIEM Value Evolution

  • SIEM's value proposition has evolved from compliance reporting to forensics and now detection.
  • Centralized data facilitates global visibility across control points, enabling effective detection rules and threat intelligence integration.
INSIGHT

Centralization Challenges

  • Centralized data platforms struggle to keep pace with expanding attack surfaces.
  • Forensic investigations in cloud environments often necessitate pulling data into SIEMs, hindering real-time detection.
ADVICE

Decoupled SIEM Considerations

  • Consider the upsides of decoupled SIEMs, such as leveraging existing storage solutions and focusing on security.
  • Acknowledge potential drawbacks like assembly complexity and performance issues.
Get the Snipd Podcast app to discover more snips from this episode
Get the app