Home / Companies / ChaosSearch / Blog / April 2024

April 2024 Summaries

4 posts from ChaosSearch

Filter
Month: Year:
Post Summaries Back to Blog
A modern data analytics stack is a collection of software tools and technologies used by enterprise teams to collect, aggregate, organize, analyze, and report on data. This stack has evolved significantly due to the increasing importance of cloud-based data warehousing services, diverse analytics use cases, cost control, administrative complexity, and data security. A typical technology stack for big data analytics includes tools for data collection and aggregation, transformation and processing, data storage, quality control, analysis, visualization, and reporting. To build a modern data analytics stack, it's essential to prioritize agnostic solutions, consider the total cost of ownership, and ensure that the stack can deliver insights for both today and the future.
Apr 25, 2024 1,343 words in the original blog post.
Datadog is a popular SaaS cloud monitoring solution that enables multiple observability use cases by collecting, monitoring, and analyzing telemetry data from various sources. However, some organizations are shifting away from Datadog for log analytics in favor of the open-source tool Grafana + Loki, citing high costs, restrictive data retention limits, vendor lock-in, and a desire for greater flexibility and scalability. Grafana is an analytics platform that allows users to ingest data from various sources, query the data, and build customized visualizations, while Loki is an open-source log aggregation system designed for horizontal scalability, cost-efficiency, high availability, and ease-of-use. By using Grafana + Loki, developers can reduce costs, avoid data retention limits, enjoy flexibility and scalability, benefit from community support, and avoid vendor lock-in, making it a viable alternative to Datadog for log analytics.
Apr 18, 2024 2,280 words in the original blog post.
Calculating log analytics ROI involves determining the value of log analytics to an organization and figuring out the total cost of ownership (TCO) of the log analytics solution. Log data contains valuable insights that can help organizations run more effectively and securely, with applications including monitoring server logs for IT and security operations, identifying potential security threats faster, meeting compliance regulations, and troubleshooting cloud infrastructure and IT issues. The cost of inaction, such as a data breach or non-compliance, can be severe, with the average cost of a data breach being $4.45 million in 2023. Log analytics solutions can help reduce costs by providing a clearer path to ROI, leveraging valuable insights from trends in log files, and mapping business benefits to cost centers. Calculating log management costs involves considering data retention, ingestion rate, and overhead, as well as the cost of inaction, and using tools like ELK stack or ChaosSearch to optimize costs and provide cost savings of up to 80%.
Apr 12, 2024 1,457 words in the original blog post.
Amazon Security Lake is a centralized platform for collecting and analyzing security data across various sources, including AWS environments, SaaS providers, on-prem environments, and cloud sources. It uses the Open Cybersecurity Schema Framework (OCSF) to normalize security data into a common format, making it easier to integrate with other tools for analysis and response. To threat hunt in Amazon Security Lake, teams need to connect their S3 bucket with an external partner that can help with data analysis. This involves integrating with tools like ChaosSearch, which allows monitoring and analyzing security content at scale while reducing operational costs. A successful threat hunt requires a clear definition of roles and responsibilities within the security team, equipping them with necessary skills and knowledge to navigate Amazon Security Lake and its associated tools. The process also involves establishing a threat hunting framework, organizing searches for signs of potential compromises or security incidents, refining Indicators of Compromise (IoCs) through machine learning and hypothesis-driven hunting, and executing threat hunts using tools like ChaosSearch to analyze security data and identify anomalies and patterns that may indicate potential security threats.
Apr 04, 2024 999 words in the original blog post.