1
00:00:00,090 --> 00:00:01,020
In this lesson,

2
00:00:01,020 --> 00:00:02,700
we're going to cover security information

3
00:00:02,700 --> 00:00:04,200
and event management systems.

4
00:00:04,200 --> 00:00:07,200
Now, log reviews are a critical part of security assurance,

5
00:00:07,200 --> 00:00:09,390
but to perform this effectively, we really need

6
00:00:09,390 --> 00:00:11,610
to first gather all of our logs from our different systems

7
00:00:11,610 --> 00:00:14,010
on our network and put them all into one place.

8
00:00:14,010 --> 00:00:15,870
Now, gathering your system logs is important,

9
00:00:15,870 --> 00:00:17,700
but gathering those logs will do you no good

10
00:00:17,700 --> 00:00:20,760
if you don't actually take time to look at those logs.

11
00:00:20,760 --> 00:00:22,110
Your log should not just be reviewed

12
00:00:22,110 --> 00:00:23,640
after an incident occurs.

13
00:00:23,640 --> 00:00:25,320
Instead, you shouldn't just be using them as part

14
00:00:25,320 --> 00:00:27,330
of your instant response, but you should really be looking

15
00:00:27,330 --> 00:00:28,530
at those logs regularly

16
00:00:28,530 --> 00:00:30,240
and routinely as part of your alerting

17
00:00:30,240 --> 00:00:31,860
and monitoring activities.

18
00:00:31,860 --> 00:00:34,020
To do this effectively though, you really do need

19
00:00:34,020 --> 00:00:35,190
to have them all in one place,

20
00:00:35,190 --> 00:00:37,620
and that is why we'll be using a SIEM.

21
00:00:37,620 --> 00:00:39,450
Now, a SIEM or a security information

22
00:00:39,450 --> 00:00:41,340
and event management system is a solution

23
00:00:41,340 --> 00:00:43,740
that provides real-time or near real-time analysis

24
00:00:43,740 --> 00:00:45,600
of your security alerts that are being generated

25
00:00:45,600 --> 00:00:47,820
by network hardware and applications.

26
00:00:47,820 --> 00:00:50,340
As we look at a SIEM, there's a lot of uses for them,

27
00:00:50,340 --> 00:00:52,170
but one of the best things that we use them for

28
00:00:52,170 --> 00:00:54,870
is to help us correlate all these various events and logs

29
00:00:54,870 --> 00:00:57,480
and incidents into one central place.

30
00:00:57,480 --> 00:00:58,950
Now, let's pretend for a moment that you're working

31
00:00:58,950 --> 00:01:01,020
as a cybersecurity analyst or professional,

32
00:01:01,020 --> 00:01:02,940
and you've been asked to go over all the system logs

33
00:01:02,940 --> 00:01:05,430
to detect any kind of unusual activities.

34
00:01:05,430 --> 00:01:07,140
Now, as you begin to look through all those logs,

35
00:01:07,140 --> 00:01:09,150
you start seeing that somebody has logged in from a VPN

36
00:01:09,150 --> 00:01:12,360
from Asia using the account for Mr. John Smith.

37
00:01:12,360 --> 00:01:14,370
Now, if John Smith is one of our employees

38
00:01:14,370 --> 00:01:16,050
and he's currently on a business trip to Asia,

39
00:01:16,050 --> 00:01:17,190
then there's probably nothing wrong

40
00:01:17,190 --> 00:01:19,650
with him logging in using a VPN from Asia.

41
00:01:19,650 --> 00:01:22,350
But if you see another log entry just a few minutes later

42
00:01:22,350 --> 00:01:24,480
that shows John Smith's security badge was used

43
00:01:24,480 --> 00:01:27,240
to unlock the server room door in your data center located

44
00:01:27,240 --> 00:01:29,550
in New York City, this is a big issue

45
00:01:29,550 --> 00:01:31,680
because John Smith can't be in both the server room

46
00:01:31,680 --> 00:01:33,510
in New York City and connecting back

47
00:01:33,510 --> 00:01:36,480
to the network using a VPN from a hotel in Asia.

48
00:01:36,480 --> 00:01:38,970
These two things can't happen at the same time,

49
00:01:38,970 --> 00:01:41,730
so based on these two log entries, we know that one

50
00:01:41,730 --> 00:01:44,610
of these two things is wrong or suspicious or malicious,

51
00:01:44,610 --> 00:01:46,470
but we don't know which one it is yet.

52
00:01:46,470 --> 00:01:48,900
Now, in this case, John is an authorized employee,

53
00:01:48,900 --> 00:01:51,000
so his logging into the VPN or going in

54
00:01:51,000 --> 00:01:53,730
and accessing the server room in itself is fine,

55
00:01:53,730 --> 00:01:56,160
but putting those two things together at the same time

56
00:01:56,160 --> 00:01:59,100
as being correlated within a short period of time flags them

57
00:01:59,100 --> 00:02:01,560
as something we need to look into further and investigate

58
00:02:01,560 --> 00:02:03,390
because this person can't be

59
00:02:03,390 --> 00:02:05,250
in both places at the same time.

60
00:02:05,250 --> 00:02:06,870
Now, since these are two disparate systems

61
00:02:06,870 --> 00:02:08,280
with one being the VPN system

62
00:02:08,280 --> 00:02:09,870
and one being the physical security system

63
00:02:09,870 --> 00:02:11,009
for your data center,

64
00:02:11,009 --> 00:02:12,840
you likely wouldn't have noticed this correlation

65
00:02:12,840 --> 00:02:14,370
across both sets of logs

66
00:02:14,370 --> 00:02:16,950
unless you were using a SIEM, which can then consolidate

67
00:02:16,950 --> 00:02:18,570
and correlate all of your system logs

68
00:02:18,570 --> 00:02:20,970
into the centralized database or repository

69
00:02:20,970 --> 00:02:23,190
because with the SIEM, it's now relatively quick

70
00:02:23,190 --> 00:02:24,840
and easy for us to identify this type

71
00:02:24,840 --> 00:02:28,620
of impossible travel across both of these disparate systems.

72
00:02:28,620 --> 00:02:31,080
Now, another example might involve a large enterprise

73
00:02:31,080 --> 00:02:32,880
with a complex network infrastructure

74
00:02:32,880 --> 00:02:35,430
that includes multiple servers, databases, firewalls,

75
00:02:35,430 --> 00:02:38,220
and thousands upon thousands of workstations.

76
00:02:38,220 --> 00:02:40,650
This organization may deploy a SIEM system

77
00:02:40,650 --> 00:02:43,440
to monitor and analyze activities across all these devices

78
00:02:43,440 --> 00:02:45,600
for any kind of potential security threats too,

79
00:02:45,600 --> 00:02:48,240
and this is another place where a SIEM helps us out.

80
00:02:48,240 --> 00:02:49,920
Now, the SIEM will be able to collect log data

81
00:02:49,920 --> 00:02:51,960
from all these different disparate sources

82
00:02:51,960 --> 00:02:54,000
and aggregate it all together for analysis

83
00:02:54,000 --> 00:02:55,890
by a cybersecurity professional.

84
00:02:55,890 --> 00:02:57,120
The SIEM can then correlate

85
00:02:57,120 --> 00:02:59,190
and analyze this data to identify patterns

86
00:02:59,190 --> 00:03:00,990
that might indicate a security threat,

87
00:03:00,990 --> 00:03:03,780
such as repeated login failures, unusual data transfers,

88
00:03:03,780 --> 00:03:05,460
or changes in file permissions.

89
00:03:05,460 --> 00:03:08,280
If the SIEM is going to detect a potential security threat,

90
00:03:08,280 --> 00:03:10,290
it can then generate an alert for the security team

91
00:03:10,290 --> 00:03:11,700
to come and investigate it.

92
00:03:11,700 --> 00:03:13,680
This can also provide us additional detailed information

93
00:03:13,680 --> 00:03:15,900
about the threat, such as the source of the attack,

94
00:03:15,900 --> 00:03:17,400
the systems or data it's targeting,

95
00:03:17,400 --> 00:03:18,960
and the methods it's using to be able

96
00:03:18,960 --> 00:03:21,150
to help our security team respond more quickly

97
00:03:21,150 --> 00:03:22,410
and more effectively.

98
00:03:22,410 --> 00:03:24,720
Now, a security and information event management system,

99
00:03:24,720 --> 00:03:26,430
or SIEM, can also be implemented

100
00:03:26,430 --> 00:03:28,200
in a couple of different ways.

101
00:03:28,200 --> 00:03:30,600
You can do this as software, hardware appliances,

102
00:03:30,600 --> 00:03:32,940
or even as an outsourced managed service

103
00:03:32,940 --> 00:03:34,680
when you're using a SIEM.

104
00:03:34,680 --> 00:03:36,540
Your SIEM can also be either agent based

105
00:03:36,540 --> 00:03:39,300
or agentless depending on how you want to collect the log data

106
00:03:39,300 --> 00:03:40,620
from all of your network devices

107
00:03:40,620 --> 00:03:42,510
and systems across that network.

108
00:03:42,510 --> 00:03:44,670
Now, an agent is a small piece of software

109
00:03:44,670 --> 00:03:46,830
that's going to be installed on each system, such as a server

110
00:03:46,830 --> 00:03:48,630
or workstation from which the SIEM needs

111
00:03:48,630 --> 00:03:50,580
to gather and collect log data.

112
00:03:50,580 --> 00:03:52,050
The agent will collect the log data

113
00:03:52,050 --> 00:03:53,730
and then send it back to the SIEM system

114
00:03:53,730 --> 00:03:55,650
for processing and correlation.

115
00:03:55,650 --> 00:03:57,930
This approach provides real-time data collection

116
00:03:57,930 --> 00:03:59,880
and can collect more detailed information,

117
00:03:59,880 --> 00:04:01,170
but it does require installing

118
00:04:01,170 --> 00:04:04,260
and maintaining the software agent on each of those systems.

119
00:04:04,260 --> 00:04:06,150
Other SIEMs though may rely on what's known

120
00:04:06,150 --> 00:04:08,040
as an agentless installation.

121
00:04:08,040 --> 00:04:09,570
Under this approach, the SIEM system

122
00:04:09,570 --> 00:04:10,890
will directly collect log data

123
00:04:10,890 --> 00:04:15,810
from each system using a standard protocol like SNMP or WMI.

124
00:04:15,810 --> 00:04:18,029
Now, this approach doesn't require installing any software

125
00:04:18,029 --> 00:04:18,863
in the systems,

126
00:04:18,863 --> 00:04:21,089
which can reduce your overall maintenance costs.

127
00:04:21,089 --> 00:04:23,730
However, it may not provide as detailed of information

128
00:04:23,730 --> 00:04:25,350
as an agent-based approach would,

129
00:04:25,350 --> 00:04:28,080
and it may not be able to collect data in near real-time

130
00:04:28,080 --> 00:04:30,450
like you can with an agent-based system.

131
00:04:30,450 --> 00:04:32,160
Now, to effectively deploy a SIEM,

132
00:04:32,160 --> 00:04:34,080
you have to consider a lot of different things.

133
00:04:34,080 --> 00:04:36,510
First, you need to be able to log all the relevant events

134
00:04:36,510 --> 00:04:38,040
and filter out anything that is not considered

135
00:04:38,040 --> 00:04:39,900
to be relevant because we consider

136
00:04:39,900 --> 00:04:42,510
that to be irrelevant data and we don't want to look at it.

137
00:04:42,510 --> 00:04:44,760
Second, we need to make sure that we can establish

138
00:04:44,760 --> 00:04:47,880
and document the scope of the events inside of our SIEM.

139
00:04:47,880 --> 00:04:49,590
Exactly what are we going to be logging

140
00:04:49,590 --> 00:04:50,910
and what's going to be considered inside

141
00:04:50,910 --> 00:04:52,650
or outside of our scope?

142
00:04:52,650 --> 00:04:54,660
Third, we need to develop use cases

143
00:04:54,660 --> 00:04:56,490
to define what a threat is.

144
00:04:56,490 --> 00:04:58,500
This helps you define exactly what you do

145
00:04:58,500 --> 00:05:00,540
and what you do not consider to be a threat,

146
00:05:00,540 --> 00:05:01,890
and then what actions you may

147
00:05:01,890 --> 00:05:04,110
or may not take based on that threat.

148
00:05:04,110 --> 00:05:06,090
This brings us to item number four where you need

149
00:05:06,090 --> 00:05:07,830
to plan out your incident response actions

150
00:05:07,830 --> 00:05:09,900
for a given threat or a given event.

151
00:05:09,900 --> 00:05:12,030
Basically, you need to know that when you see this type

152
00:05:12,030 --> 00:05:13,650
of thing happening and alerting,

153
00:05:13,650 --> 00:05:15,960
what are the actions you want your team to take?

154
00:05:15,960 --> 00:05:17,190
That's what we're talking about here.

155
00:05:17,190 --> 00:05:19,770
It's the pre-planned responses for any kind of given threat

156
00:05:19,770 --> 00:05:22,350
that you may end up facing out in the real world.

157
00:05:22,350 --> 00:05:24,960
Fifth, we need to establish a ticketing process.

158
00:05:24,960 --> 00:05:26,790
That way we could track all these different events

159
00:05:26,790 --> 00:05:27,990
that we're flagging.

160
00:05:27,990 --> 00:05:30,390
This way, as we go into our SIEM, we may see something

161
00:05:30,390 --> 00:05:32,970
that's unusual, like my example earlier when we saw somebody

162
00:05:32,970 --> 00:05:35,040
logging in from Asia and logging at the local office

163
00:05:35,040 --> 00:05:36,000
at the same time.

164
00:05:36,000 --> 00:05:38,970
We would say that looks suspicious, so we will flag it.

165
00:05:38,970 --> 00:05:41,220
Now, once we flag it, we need to have some sort

166
00:05:41,220 --> 00:05:43,290
of a ticketing system created so we can be able

167
00:05:43,290 --> 00:05:45,240
to track it all the way through the process

168
00:05:45,240 --> 00:05:46,500
to make sure nobody drops it

169
00:05:46,500 --> 00:05:48,330
and it doesn't get forgotten about.

170
00:05:48,330 --> 00:05:51,240
Sixth, we need to schedule regular threat hunting.

171
00:05:51,240 --> 00:05:52,620
Now, by doing this, we want to ensure

172
00:05:52,620 --> 00:05:54,240
that we're not missing any important events

173
00:05:54,240 --> 00:05:55,890
that may have escaped an alert.

174
00:05:55,890 --> 00:05:57,780
By setting up and conducting threat hunting,

175
00:05:57,780 --> 00:06:00,390
we're going to be able to catch bad actors doing bad things

176
00:06:00,390 --> 00:06:02,490
that may have bypassed our alerts.

177
00:06:02,490 --> 00:06:04,860
And finally, we move into our seventh item that we need

178
00:06:04,860 --> 00:06:06,720
to consider, which is to provide auditors

179
00:06:06,720 --> 00:06:08,850
and analysts an evidence trail.

180
00:06:08,850 --> 00:06:10,260
As you probably guessed by now,

181
00:06:10,260 --> 00:06:12,600
a SIEM is a centralized repository that has lots

182
00:06:12,600 --> 00:06:14,880
of different data, so it becomes a great place for auditors

183
00:06:14,880 --> 00:06:16,890
and analysts to look through as they begin

184
00:06:16,890 --> 00:06:19,680
to do their analysis for your compliance reports.

185
00:06:19,680 --> 00:06:21,900
Now, there's a lot of different SIEM solutions out there,

186
00:06:21,900 --> 00:06:24,390
including both commercial and open source varieties

187
00:06:24,390 --> 00:06:26,580
that includes things like Splunk, ELK,

188
00:06:26,580 --> 00:06:29,880
or the Elastic Stack, ArcSight and QRadar.

189
00:06:29,880 --> 00:06:31,110
If you hear any of these names,

190
00:06:31,110 --> 00:06:33,720
you should know they have the ability to act as a SIEM,

191
00:06:33,720 --> 00:06:34,950
but beyond that, you really don't need

192
00:06:34,950 --> 00:06:37,770
to know how to use them or operate them for your exam.

193
00:06:37,770 --> 00:06:39,750
Now, like I said, there's a lot of open source tools

194
00:06:39,750 --> 00:06:41,940
that make a great addition to your own practice labs

195
00:06:41,940 --> 00:06:43,170
and your own home network

196
00:06:43,170 --> 00:06:45,000
because if you're building out your own home network,

197
00:06:45,000 --> 00:06:45,960
this will give you the experience

198
00:06:45,960 --> 00:06:47,490
with these tools hands-on,

199
00:06:47,490 --> 00:06:49,350
which in turn makes you a much better analyst

200
00:06:49,350 --> 00:06:50,490
out in the real world,

201
00:06:50,490 --> 00:06:51,750
and so that's a reason why it's important

202
00:06:51,750 --> 00:06:53,040
to look at these different SIEMs

203
00:06:53,040 --> 00:06:55,290
and maybe even play with them in your own network.

204
00:06:55,290 --> 00:06:56,400
Now, let's take a look at some

205
00:06:56,400 --> 00:06:58,320
of these different SIEMs and understand what they are.

206
00:06:58,320 --> 00:06:59,760
First, we have Splunk.

207
00:06:59,760 --> 00:07:01,320
Now, Splunk is a market-leading

208
00:07:01,320 --> 00:07:04,050
big data information-gathering and analysis tool

209
00:07:04,050 --> 00:07:06,690
that can import machine-generated data via a connector

210
00:07:06,690 --> 00:07:08,490
or a visibility add-on.

211
00:07:08,490 --> 00:07:10,410
Now, Splunk is really good at connecting lots

212
00:07:10,410 --> 00:07:12,030
of different data systems and sources

213
00:07:12,030 --> 00:07:13,920
into one consolidated area.

214
00:07:13,920 --> 00:07:15,480
In fact, it has different connectors built

215
00:07:15,480 --> 00:07:17,190
for most network operating systems

216
00:07:17,190 --> 00:07:19,350
and different application formats as well.

217
00:07:19,350 --> 00:07:21,900
Essentially, all the data from all these different systems

218
00:07:21,900 --> 00:07:24,360
can be indexed as it's taken off of those systems

219
00:07:24,360 --> 00:07:26,580
and then written into a centralized database store

220
00:07:26,580 --> 00:07:28,200
using a common format.

221
00:07:28,200 --> 00:07:29,490
This allows Splunk to be able to go

222
00:07:29,490 --> 00:07:31,590
through all the historical or real-time data

223
00:07:31,590 --> 00:07:32,520
and be able to search through all

224
00:07:32,520 --> 00:07:34,680
of it using its proprietary search algorithms

225
00:07:34,680 --> 00:07:36,960
called the Search Processing Language.

226
00:07:36,960 --> 00:07:38,280
Now, once you get those results,

227
00:07:38,280 --> 00:07:40,740
you can start visualizing it using different tools.

228
00:07:40,740 --> 00:07:43,560
So if you're using Splunk, it looks something like this.

229
00:07:43,560 --> 00:07:46,410
Notice here what I have is what looks like a dashboard

230
00:07:46,410 --> 00:07:49,020
and I can see all my important information in one place.

231
00:07:49,020 --> 00:07:51,780
I see I have lots of data, I see trends going up or down.

232
00:07:51,780 --> 00:07:54,270
I see events over time, and I can actually drill down

233
00:07:54,270 --> 00:07:56,340
and click into each one of those by going in

234
00:07:56,340 --> 00:07:58,980
and look at the data behind it as well if I need to.

235
00:07:58,980 --> 00:08:00,600
Now, Splunk is a really great tool

236
00:08:00,600 --> 00:08:01,740
and it can be installed locally

237
00:08:01,740 --> 00:08:03,600
or as a cloud-based solution.

238
00:08:03,600 --> 00:08:05,910
When you buy Splunk, it comes with a lot of templates

239
00:08:05,910 --> 00:08:07,530
and pre-configured dashboards,

240
00:08:07,530 --> 00:08:09,240
as well as security intelligence searches

241
00:08:09,240 --> 00:08:11,130
and incident response workflows.

242
00:08:11,130 --> 00:08:12,780
Splunk is probably one of the biggest players

243
00:08:12,780 --> 00:08:13,800
in the marketplace,

244
00:08:13,800 --> 00:08:16,020
and it's a great SIEM for you to consider.

245
00:08:16,020 --> 00:08:18,750
Second, we have ELK or the Elastic Stack.

246
00:08:18,750 --> 00:08:21,360
Now, ELK or the Elastic Stack is a collection of free

247
00:08:21,360 --> 00:08:24,240
and open source SIEM tools that provide storage, search,

248
00:08:24,240 --> 00:08:26,400
and analysis functions.

249
00:08:26,400 --> 00:08:28,350
Now, with Elk and Elastic Stack, it's actually made up

250
00:08:28,350 --> 00:08:29,910
of four different components.

251
00:08:29,910 --> 00:08:31,980
These are the Elasticsearch, which covers the query

252
00:08:31,980 --> 00:08:34,740
and analytics, Logstash, which is your log collection

253
00:08:34,740 --> 00:08:36,840
and normalization process, Kibana,

254
00:08:36,840 --> 00:08:38,280
which does your visualization

255
00:08:38,280 --> 00:08:40,530
and Beats, which is your endpoint collection agents

256
00:08:40,530 --> 00:08:42,450
that are installed on your machines.

257
00:08:42,450 --> 00:08:43,740
The way these all work together

258
00:08:43,740 --> 00:08:45,210
is that you're going to have different beats installed

259
00:08:45,210 --> 00:08:46,680
on different servers or hosts,

260
00:08:46,680 --> 00:08:48,750
and they can then send out either directly things back

261
00:08:48,750 --> 00:08:52,200
to Elastic Stack, or it can go into Logstash first.

262
00:08:52,200 --> 00:08:54,390
Now, when it goes into Log Stash first,

263
00:08:54,390 --> 00:08:55,710
it's going to be doing all the parsing

264
00:08:55,710 --> 00:08:56,880
and normalization for you,

265
00:08:56,880 --> 00:08:59,490
and then it sends it over to the Elasticsearch.

266
00:08:59,490 --> 00:09:01,140
If you go directly into Elasticsearch,

267
00:09:01,140 --> 00:09:03,870
it has to be in a format that it already understands.

268
00:09:03,870 --> 00:09:06,480
Now, Elasticsearch is that centralized data store,

269
00:09:06,480 --> 00:09:07,530
and you're really not going to go in

270
00:09:07,530 --> 00:09:09,810
and look at Elastic itself to look at the data.

271
00:09:09,810 --> 00:09:10,920
Instead, most of the time,

272
00:09:10,920 --> 00:09:13,800
you're going to use a visualization tool like Kibana.

273
00:09:13,800 --> 00:09:15,090
Kibana goes into Elastic,

274
00:09:15,090 --> 00:09:17,580
and then visualizes all the data in a way that makes it easy

275
00:09:17,580 --> 00:09:19,410
for us to see and understand.

276
00:09:19,410 --> 00:09:22,170
Just like Splunk, ELK Stack may be installed locally

277
00:09:22,170 --> 00:09:24,210
or as a cloud-based solution.

278
00:09:24,210 --> 00:09:25,680
Third, we have ArcSight.

279
00:09:25,680 --> 00:09:27,360
Now, ArcSight is a SIEM log management

280
00:09:27,360 --> 00:09:29,100
and analytics software that can be used

281
00:09:29,100 --> 00:09:30,960
for compliance reporting for legislation

282
00:09:30,960 --> 00:09:34,680
and regulations like HIPAA, SOX and PCI DSS.

283
00:09:34,680 --> 00:09:36,900
When you look at ArcSight, it looks a lot like any

284
00:09:36,900 --> 00:09:38,550
of the other dashboards I've already shown you,

285
00:09:38,550 --> 00:09:40,590
and again, you can drill down into that information

286
00:09:40,590 --> 00:09:42,990
and display it in lots of different ways too.

287
00:09:42,990 --> 00:09:44,610
Fourth, we have QRadar.

288
00:09:44,610 --> 00:09:47,220
Now, QRadar is another SIEM log management analytics

289
00:09:47,220 --> 00:09:48,840
and compliance reporting platform,

290
00:09:48,840 --> 00:09:51,030
but this one was created by IBM.

291
00:09:51,030 --> 00:09:52,110
Now, QRadar does a lot

292
00:09:52,110 --> 00:09:53,760
of the same stuff we've already talked about,

293
00:09:53,760 --> 00:09:56,340
and again, it comes with a really nice looking dashboard.

294
00:09:56,340 --> 00:09:58,350
As you look at the dashboard, you get different things

295
00:09:58,350 --> 00:10:00,300
that you're going to be looking at, and you can click on those

296
00:10:00,300 --> 00:10:02,610
to dive into them and get more details about your network

297
00:10:02,610 --> 00:10:04,140
and about your events.

298
00:10:04,140 --> 00:10:06,810
Now, in the real world, which of these SIEMs should you use?

299
00:10:06,810 --> 00:10:08,580
Well, that depends which company you're trying

300
00:10:08,580 --> 00:10:11,280
to get a job at or which company do you already work for?

301
00:10:11,280 --> 00:10:12,810
I've worked at a lot of different organizations

302
00:10:12,810 --> 00:10:14,160
over the years, and we've used several

303
00:10:14,160 --> 00:10:16,617
of these different tools, including Splunk, ELK Stack,

304
00:10:16,617 --> 00:10:19,560
and ArcSight at different organizations I've worked with.

305
00:10:19,560 --> 00:10:21,420
So I've had a lot of experience with a lot of these,

306
00:10:21,420 --> 00:10:22,800
and you're probably wondering if one is better

307
00:10:22,800 --> 00:10:24,060
than the other, and honestly,

308
00:10:24,060 --> 00:10:26,070
it really does depend on your use case.

309
00:10:26,070 --> 00:10:27,180
But at the end of the day,

310
00:10:27,180 --> 00:10:28,500
you're probably not going to be the one choosing

311
00:10:28,500 --> 00:10:29,490
which SIEM to use,

312
00:10:29,490 --> 00:10:30,840
and instead, the SIEM you're going to use

313
00:10:30,840 --> 00:10:32,340
is really going to come down to which one your company

314
00:10:32,340 --> 00:10:33,300
is already using

315
00:10:33,300 --> 00:10:35,670
or which one your boss has chosen for your department

316
00:10:35,670 --> 00:10:37,500
to use, especially if you're in the entry

317
00:10:37,500 --> 00:10:39,630
or mid-level portion of your career.

318
00:10:39,630 --> 00:10:41,430
So remember, SIEMs are essential tools

319
00:10:41,430 --> 00:10:42,930
in the cybersecurity landscape

320
00:10:42,930 --> 00:10:45,120
since the SIEM is used to provide real-time analysis

321
00:10:45,120 --> 00:10:46,830
of your security alerts that are being generated

322
00:10:46,830 --> 00:10:49,200
by your applications or network hardware.

323
00:10:49,200 --> 00:10:50,850
Your SIEM can either use agent-based

324
00:10:50,850 --> 00:10:52,140
or agentless approaches,

325
00:10:52,140 --> 00:10:54,060
and there are many examples of SIEMs on the market,

326
00:10:54,060 --> 00:10:57,980
including Splunk, ELK or Elastic Stack, ArcSight and QRadar.

