Skip to main content

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

  • November 3, 2025
  • 0 replies
  • 13 views

chuvakin
Staff
Forum|alt.badge.img+9

Guest:

Topics: 

SIEM and SOC

 

Subscribe at Spotify

Subscribe at Apple Podcasts

Subscribe at YouTube

Topics covered:

  • Are we really coming  to “access to security data” and away from “centralizing the data”?
  • How to detect without the same storage for all logs?
  • Is data pipeline a part of SIEM or is it standalone? Will this just collapse into SIEM soon?
  • Tell us about the issues with log pipelines in the past?
  • What about enrichment? Why do it in a pipeline, and not in a SIEM?
  • We are unable to share enough practices between security teams. How are we fixing it? Is pipelines part of the answer?
  • Do you have a piece of advice for people who want to do more than save on their SIEM costs?

0 replies

Be the first to reply!