Company
Date Published
Author
Daniel Berman
Word count
1520
Language
English
Hacker News points
None

Summary

The article reviews five commercial Security Information and Event Management (SIEM) systems—AlienVault USM, Micro Focus ArcSight ESM, IBM Security QRadar, Splunk Enterprise, and LogRhythm—by evaluating their intended audience, deployment models, features, and strengths and weaknesses. AlienVault USM is deemed suitable for small to medium organizations but lacks certain advanced features and requires technical expertise for configuration. ArcSight ESM is recognized as a comprehensive solution for large enterprises but is noted for its complexity and high cost. QRadar is praised for its robustness and scalability but criticized for being overwhelming and not user-friendly. Splunk Enterprise offers high flexibility and extensibility, allowing for customization through add-ons, but its base system lacks core functionalities. LogRhythm is highlighted for its extensive security features and reporting capabilities, though it is costly and requires expert configuration. The article concludes by suggesting that organizations choose a SIEM system based on their size and specific needs, with recommendations tailored to different organizational requirements and resources.