Home / Companies / ChaosSearch / Blog / June 2024

June 2024 Summaries

3 posts from ChaosSearch

Filter
Month: Year:
Post Summaries Back to Blog
Innovating Security with Managed Detection & Response (MDR) and ChaosSearch, MDR services provide organizations with 24/7 security monitoring and threat detection, proactive threat hunting, and incident response capabilities, delivered by Managed Security Service Providers (MSSPs). The biggest challenges faced by MDRs are data fragmentation and high data retention costs at scale. To address these issues, top MDR vendors like Armor, Blackpoint, and Levelblue are integrating Chaos LakeDB into their cybersecurity tooling as an Elasticsearch replacement to aggregate security data from all sources in cost-effective cloud object storage, index it, and run SQL queries on the data to support proactive threat hunting and long-term analytics use cases. By doing so, MDRs can reduce costs and complexity while enabling unlimited data retention for much cheaper than alternative analytics solutions.
Jun 20, 2024 1,145 words in the original blog post.
In order to effectively detect and investigate security incidents, organizations must prioritize security logging and monitoring. However, common mistakes such as insufficient logging, poor log storage practices, inadequate monitoring and alerting, ignoring log analysis, and lack of log integrity and confidentiality can compromise the effectiveness of these measures. By avoiding these mistakes and implementing best practices, organizations can enhance their security posture and protect themselves against evolving cybersecurity threats. Effective security logging and monitoring requires a combination of automated tools, regular review and update of alerts and thresholds, comprehensive analysis of logs, secure storage and transmission of logs, and strict access controls to prevent unauthorized access. Utilizing resources like OWASP and implementing a modular observability stack can help organizations maintain proactive security controls and improve their overall security posture.
Jun 13, 2024 1,241 words in the original blog post.
AWS offers a comprehensive logging service with CloudTrail, which provides detailed visibility into account activity, including Identity and Access Management (IAM) logs, error code and message logs, CloudTrail Insights event logs, and Amazon Elastic Compute Cloud (EC2) logs. GCP also offers robust logging services, including Google Cloud Logging, user-written logs, component logs, and cloud security logs, such as Cloud audit logs and access transparency logs. Both platforms have their strengths and weaknesses, with AWS being favored for its extensive integration and comprehensive logging tools, while GCP stands out for its centralized approach and strong security features. A third-party log management solution like ChaosSearch can help simplify cloud logging by leveraging low-cost cloud object storage to reduce pricing costs. Cloud operations teams use these logs to maintain stability, optimize performance, control costs, and govern data usage, but often face challenges with log retention and cost, leading them to rethink their enterprise data architectures and explore alternative solutions.
Jun 06, 2024 1,726 words in the original blog post.