

EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect
Jul 14, 2025
Svetla Yankova, Founder and CEO of Citreno, dives into the paradox of SIEM systems in modern security. Despite hefty investments in logging tools, many organizations fail to detect threats effectively. She discusses challenges like data enrichment and the importance of context for SOC analysts. Svetla also addresses common SIEM pitfalls and the expectations surrounding technology migrations. Additionally, she ponders the role of AI in security, questioning whether it's repeating the past mistakes of SOAR vendors or creating new ones.
AI Snips
Chapters
Transcript
Episode notes
SIEM Operational Complexity Problems
- Organizations collect many logs but struggle to detect threats due to operational complexity and overwhelming data volume.
- SIEM systems often become glorified grep tools lacking meaningful semantic interpretation for detection.
SIEM Data Normalization Regression
- Early SIEM products insisted on normalized, opinionated data models which aided detection.
- Later shift to ingest-first approaches made normalization optional, shifting complexity to human analysts and making detection harder.
Context Complexity in SOC Analysis
- Basic alert context like asset info is generally handled well but richer, correlated context remains lacking.
- Lack of integrated feedback loops prevents mature understanding of environment and leads to automation gaps.