Why isn’t “Just SIEM” Enough?
There’s a legacy connotation attached to SIEM that has led to vendors advertising themselves as some iteration of a next-generation solution. But is it necessary? I’ve been struggling to find solutions that would be classified as “legacy SIEM”—that is, SIEM without some sort of automation, response, or anomaly detection capabilities or modules. It makes sense…