7MS #338: SIEMple Tests for Your SIEM Solution
Today's episode talks about some SIEMple tests you can run on your SIEM (OMg see what I did there? I took the word simple and made it SIEMple. Genius stuff, right? And there's no extra charge for it!). And if you're just now starting to shop around for a SIEM, this episode also has an extensive questionnaire you can use to put your vendors' feet to the fire and see what they're made of! Along with today's episode, I'm releasing a companion gist that contains:
-
Questionnaire - a series of questions you can ask SIEM vendors to gather as many data points about their products and services as possible
-
SIEM tests - a few tests you can conduct on your internal/external network to see if your SIEM solution indeed coughs up alerts
Enjoy!