![]() |
Can OSSIM be considered a SIEM? Is it enterprise ready? Sat, 20 Jun 2009
The story starts as following. A couple of years ago Dr. Anton Chuvakin (for those who might not know him a well renowned security professional and speaker) made a prediction for 2006: that a Credible Open-Source SIM would not arrive.
Yesterday I followed a couple of quick twitter exchanges where I'd like to quote the most significant ones:
So, there it is, Andrew Hay (another renowned security expert) and Anton say that:
Well. Guess I'll have to prove them wrong ;-). And on top I'm not pissed off, so I guess I'm growing up :-)). So what do I need? I for myself have received news/feedback of pretty big OSSIM installations and have had my hands on another bunch of them. Ranging from 100 person Real Estate companies to >40000pc governmnet environments with distributed deployments and thousands of events per second (this last one using the COSS version of course). But, the point as mentioned by Anton is that we don't have our hands in it, the testimonial has to come from someone who's got a deployment running not managed by us. Both S/MB as well as large enterprise deployments are valid since there are two points to prove. I'd really like to hear from a large company which is supposedly using Splunk+OSSIM, can't say the name but that would be a good example :-). So, if any of you reading this is in that situation please let Mr. Chuvakin and Mr. Hay know about it so they hopefully can change their minds on the subject. There's contact information on their respective homepages. Otherwise I'll have to eat my words and admit that OSSIM is no Open Source SIEM (like in The Matrix, "there's no spoon"). Thanks in advance for any help :-) PS: BTW, we did a first run of the webinar yesterday, thanks everybody for assisting and apologies for the, well, mishappenings. I got quite nervous, next demo will be better. Edit 2009/06/20: Fixed a misunderstanding on who predicted what, see the comments.
posted at: 07:03 | path: /personal | permanent link to this entry | 6 comments | Webinar around OS Security and OSSIM Mon, 15 Jun 2009 I got talked into speaking at a webinar next week (well, we've got another one this week but it's already crowded so I'm only posting next weeks link. And since this week's is my first webinar ever the second one should be better anyway), namely about Open Source Information Security: Reduce Costs while Improving Security Profile & Compliance. That's it, nice and short name as I like and love them.
I don't know how it work out, guess it shouldn't be very boring and registration is free so if you want to join in you're more than welcome. Additionally you get something called CPE credits for attending (sounds like experience points ;-)).
During this seminar we will describe and demonstrate the implementation of an enterprise ready system comprised of more than 15 well known Open Source tools, with the goal of showing attendees that Open Source technology can be leveraged to provide a reliable and comprehensive alternative to commercial solutions, at a fraction of the cost, without sacrificing functionality or ease of use.
posted at: 14:08 | path: /ossim | permanent link to this entry | 5 comments | |
Categories
/ (66) Dominique Karg (feel free to get in touch) Friend's blogs:
Archives
2010-Apr Tags | |||||||||||||||||||||||||||||||||||||||||||||||||



