Critical Analysis needed. Please follow the instructions on the paper. Thank you
One of the leaders in the field of SIEM software is Splunk Enterprise. A leader in this field means that they have the vision of what a security solution mean and the ability to get the solution to multiple companies. “Splunk is widely deployed by IT operations and application support teams for log management, analytics, monitoring, and advanced search and correlation.” (Kavangh, Rochford, 2015) Splunk has been designed for an enterprise size company but can support any size business. “Splunk can be deployed on Splunk can be deployed for SIEM as onpremises software, in a public or private cloud, as a SaaS offering from Splunk (Splunk Cloud), or in any combination (hybrid).” (Kavangh, Rochford, 2015) “Organizations that require an SIEM platform that can be customized to support extensive analytics functions and a variety of log formats, and those with use cases that span security and IT operations support, should consider Splunk.” (Kavangh, Rochford, 2015) The strengths of Splunk Enterprise software is that the solution supports a large number of external threat intelligence feeds from multiple sources. The solution is very easy to use and the speed and scalability of the software is not limited to SQL databases. “Easy to create new reports or modify existing ones. Data can be visualized in many ways including tables, charts or scatterplots” (Splunk, N.D.) Most SIEM solutions only focus on the known threats when it comes to detection but Splunk Enterprise uses “‘Known threat’ detection, and can also index “nonsecurity” data to identify the outliers that may be “unknown threats”” (Splunk, N.D.) Splunk Enterprise has enterprise level availability and scale to accommodate terabytes of data per day. “The High Performance Analytics Store and other acceleration technologies enable you to generate reports on big data at lightning fast speeds.” (Splunk, N.D.) This software solution will help the company manage of its assets and collect all of the data from the antivirus and other security solutions.
There are some downsides when picking a company that is known as a leader in the SIEM. This product is mainly designed for large scale Enterprise Company so the support for predefined conditions is basic. If the company is going to be experiencing a extremely large data flow they might want to consider seeking another company since the pricing is based on volume of data that is indexed per day. (Kavangh, Rochford, 2015) “Workflow and case management functions lag behind those of competitors. Organizations with mature SOC processes may require customization or integrations with thirdparty technologies for these functions.” (Kavangh, Rochford, 2015)
References:
Gartner, N.D. Security Inforemation and Event Management retrieved from http://www.gartner.com/it-glossary/security-information-and-event-management-siem
Kavangh, Kelly,. Rochford,. Oliver 20 July 2015. Magic Quadrant for Security Information and Event Management retrieved from https://scadahacker.com/library/Documents/White_Papers/Gartner%20-%20Magic%20Quadrant%20for%20SIEM%20-%202015.pdf
N.A, N.D, Using Splunk Software as a Siem retrieved from https://www.splunk.com/web_assets/pdfs/secure/Splunk_as_a_SIEM_Tech_Brief.pdf
N.A, N.D, Splunk Enterprise retrieved from http://www.splunk.com/en_us/products/splunk-enterprise.html