Skip to content
Discussion options

You must be logged in to vote

Often, a generic SIEM will have some capabilities that aren't available in SO -- for example, a built-in asset inventory module or an integration with vulnerability scanners to adjust the severity of alerts. SO is optimized more around monitoring and active investigation. Also, SIEMs generally make it easier to write detections across different datasets (ie "If you see this malicious traffic followed by this response and if the server is running Linux and if the web server on it is Apache, raise an alert").

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by shimanotaka
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants