Discussion about this post

User's avatar
McParty's avatar

Ingesting logs in to any SIEM without a use case is not cost effective - with platforms like Splunk, there are costs associated with data ingestion.

Read the docs about the logs You are looking to ingest.

You will find some are rubbish and offer no security value or enrichment.

Expand full comment
Su W's avatar

Thanks for this article! 😇

Expand full comment
2 more comments...

No posts