UnderDefense Cybersecurity的动态

UnderDefense Cybersecurity转发了

查看Nazar Tymoshyk的档案

CEO at UnderDefense Cyber Security

Hey community, one of my engineers recently prepared a comparison of OpenSearch vs. Elastic Cloud for SIEM purposes. I'd love to hear your thoughts or experiences! Have you utilized pure OpenSearch as a SIEM for SOC operations for 30+ analysts? We're primarily relying on Splunk and Elastic Cloud and are very happy with both, but I'm curious to learn how OpenSearch stacks up in real-world scenarios. Leaving this matrix for comments https://lnkd.in/dDJgdwAx

  • 该图片无替代文字
Prabhat Sharma

Building world's simplest and most efficient observability platform

4 个月

While built for observability logs, you should really check https://github.com/openobserve/openobserve . It does all in the above list and more and much more efficiently.

Bohdan Skorynovych

Senior Security Engineer at Welltech

4 个月

Lot's of "No Support" values are actually supported with plugins and automations around the Opensearch: 1. https://opensearch.org/docs/latest/security-analytics/ 2. https://github.com/aws-samples/siem-on-amazon-opensearch-service/tree/main

Zack Tembi

Navigating the future of software

4 个月

Nazar Tymoshyk Are you using Cribl?

Chaitanya Sistla

Principal Solutions Architect | 16x Certified in Cloud, DevOps, Security & Data | Entrepreneurial Resilience in Action

4 个月

I have used OpenObserve in my previous company for SIEM purpose as well. https://github.com/openobserve/openobserve O2 stores all the logs in an object storage which was source to ArcticWolf that powered it to take over as MDR base. While observability is the focus, it solves many other security challenges like allowing you to create realtime insights, aggregations and transformations over the ingested data to achieve security objectives.

It's great to see such a thorough comparison being shared. OpenSearch certainly has potential, and real-world experiences can provide valuable insights. How have you found the integration process with your existing tools?

回复

OKTA IDP logs ingestion via API is supported or i'm wrong ?

回复

So you compare free elastic and paid version (SIEM) that add ingestion and aggregation functionality and show that they have differences? Really?

回复
查看更多评论

要查看或添加评论,请登录