Discussion about this post

User's avatar
Threatyness's avatar

Ingesting logs in to any SIEM without a use case is not cost effective - with platforms like Splunk, there are costs associated with data ingestion.

Read the docs about the logs You are looking to ingest.

You will find some are rubbish and offer no security value or enrichment.

2 more comments...

No posts

Ready for more?