Cloud Security Podcast by Google

EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect

Jul 14, 2025
Svetla Yankova, Founder and CEO of Citreno, dives into the paradox of SIEM systems in modern security. Despite hefty investments in logging tools, many organizations fail to detect threats effectively. She discusses challenges like data enrichment and the importance of context for SOC analysts. Svetla also addresses common SIEM pitfalls and the expectations surrounding technology migrations. Additionally, she ponders the role of AI in security, questioning whether it's repeating the past mistakes of SOAR vendors or creating new ones.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

SIEM Operational Complexity Problems

  • Organizations collect many logs but struggle to detect threats due to operational complexity and overwhelming data volume.
  • SIEM systems often become glorified grep tools lacking meaningful semantic interpretation for detection.
INSIGHT

SIEM Data Normalization Regression

  • Early SIEM products insisted on normalized, opinionated data models which aided detection.
  • Later shift to ingest-first approaches made normalization optional, shifting complexity to human analysts and making detection harder.
INSIGHT

Context Complexity in SOC Analysis

  • Basic alert context like asset info is generally handled well but richer, correlated context remains lacking.
  • Lack of integrated feedback loops prevents mature understanding of environment and leads to automation gaps.
Get the Snipd Podcast app to discover more snips from this episode
Get the app