EP250 The End of "Collect Everything"? Moving from Centralization to Data Access? - podcast episode cover

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

Nov 03, 202529 minSeason 1Ep. 250
--:--
--:--
Download Metacast podcast app
Listen to this episode in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episode description

Guest:

Topics:

  • Are we really coming to "access to security data" and away from "centralizing the data"?
  • How to detect without the same storage for all logs?
  • Is data pipeline a part of SIEM or is it standalone? Will this just collapse into SIEM soon?
  • Tell us about the issues with log pipelines in the past?
  • What about enrichment? Why do it in a pipeline, and not in a SIEM?
  • We are unable to share enough practices between security teams. How are we fixing it? Is pipelines part of the answer?
  • Do you have a piece of advice for people who want to do more than save on their SIEM costs?

Resources:

For the best experience, listen in Metacast app for iOS or Android