Enterprise Security Weekly (Audio)

Setting up your SIEM for success - Pitfalls to preclude and tips to take - Geoff Cairns, Neil Desai - ESW #400

9 snips
Mar 31, 2025
Neil Desai, a product strategist at Graylog with extensive experience in building SOCs and SIEMs, joins the conversation alongside Jeff Karens, a principal analyst at Forrester. They dive deep into the critical elements of setting up a successful SIEM, from ensuring the correct logs are enabled to the importance of cross-department collaboration. They also explore the cutting-edge trends in identity and access management, including the challenges of deepfake detection and advancements in zero trust strategies, all while sharing anecdotes that lighten the heavy tech talk.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ADVICE

Collaborate for Successful SIEM

  • Engage stakeholders in understanding log environment before SIEM deployment.
  • Collaborate with sysadmins to verify logging configurations and build trust by giving access back to them.
ADVICE

Verify SIEM Purpose and Data

  • Understand the problem your SIEM is solving before buying or deploying it.
  • Verify what logs are coming in regularly to ensure accurate detection and alerting.
ADVICE

Implement a Logging Policy

  • Create and get sign-off on a clear logging policy covering log content and retention.
  • Use this policy to guide configuration and auditing of log sources consistently.
Get the Snipd Podcast app to discover more snips from this episode
Get the app