SIEM License Management — Staying in Control of Ingestion Costs - Exabeam

SIEM License Management — Staying in Control of Ingestion Costs

Published
August 01, 2023

Author

Reading time
5 mins

Managing the cost of a SIEM solution can indeed be a challenging task. During my recent attendance at Infosecurity Europe, the most common concern raised from security operations center (SOC) managers and architects was regarding SIEM ingestion costs. The substantial shift toward SaaS adoption in the last two to three years has rapidly compelled almost all SIEM vendors to adopt ingestion-based licensing models. As a result of this transition to SaaS, the majority of SIEM vendors have embraced ingestion-based licensing, which has introduced complexities in managing licenses. These costs can vary significantly and have the potential to spiral out of control if not effectively managed. As an illustration, let’s look at a couple of examples from public price books offering SIEM as a service:

  • Splunk Cloud: Offers a plan priced at $92,000 per annum for a daily ingest of 100GB. This plan is EMEA-based hosting in AWS
  • Azure Sentinel: Offers a plan priced at $134,000 per annum for a daily ingest of 100GB. This plan is UK-based hosting in Azure.

It is evident that SIEM vendors encourage users to ingest as much data as possible without offering efficient ways of predicting or controlling ingestion for the end user. Recognizing this challenge, Exabeam has addressed this critical pain point based on feedback from numerous clients worldwide and introduced functionality to combat this issue and optimize SIEM license management. 

Three key features were released earlier this year for Exabeam, which help manage SIEM ingestion and consequently reduce long-term SIEM costs:

Log Stream

SIEM License Management — Staying in Control of Ingestion Costs
Fig 1. Log Stream shows that a “checkpoint network traffic success accept” event registers two to three times higher than the second most popular parser.

With Log Stream, security analysts and architects can visualize and manage parsers in greater detail. This feature displays which parsers are active and how they’re being used. From a license management perspective, analysts can order parsers by event usage over the last 24 hours to identify the most popular parsed events. 

By identifying less useful events, such as the example of checkpoint network traffic success accept registering two to three times higher than the second most popular parser, analysts can choose to turn them off and reduce ingestion by more than 50%. Additionally, parser calibration scores are provided, helping analysts determine areas where improvements in parsing can be made. 

Outcomes Navigator

SIEM License Management — Staying in Control of Ingestion Costs
Fig 2. Outcomes Navigator provides recommendations to improve the Lateral Movement use case.

Outcomes Navigator allows analysts to evaluate their use case coverage within the SIEM system. It provides feedback on the coverage levels for key security use cases based on the current logging.The recommendations generated by Outcomes Navigator play a crucial role in license management. By analyzing how well a log source is being parsed and used to achieve the relevant security-based outcomes, analysts can identify opportunities to improve parser calibration and extract more value from the already-ingested data. 

The screenshot above displays recommendations to improve the Lateral Movement use case. It informs the analyst that, despite receiving relevant log sources for Lateral Movement coverage, they may not be fully calibrated. Calibration scoring is based on the extraction of relevant metadata from the log itself. Exabeam ranks parser calibration and provides recommendations for improvement. From a license management perspective, this will add value to the data that is already being ingested.

Why pay for data to be ingested if it’s not being utilized correctly? This is a significant trend we observe in SIEM. 

Service Health and Consumption

SIEM License Management — Staying in Control of Ingestion Costs
Fig 3. Service and Health Consumption displays where the ingested data is coming from per vendor and per parser.

The Service Health and Consumption feature provides a simple graphic breakdown of SIEM ingestion, indicating where the data is coming from per vendor and per parser. In this case illustrated in figure 3 above, BeyondTrust is sending approximately 5GB of data to the SIEM system each day. This visual representation helps security professionals identify potential ingestion surprises and understand the sources of data more effectively. 

Conclusion

In conclusion, controlling SIEM costs can be achieved through two key areas:

  1. Visualizing data ingestion in detail
  2. Understanding where ingestion is occurring and assessing the effectiveness of the parsing process

The Exabeam Security Operations Platform excels in both aspects, requiring no advanced training and ensuring that your investment in data ingestion is optimized. 

In the next part of this SIEM license management series, we will explore how Exabeam can assist in log filtering to further reduce the overhead of log management

If you’d like to explore how these features can efficiently control your SIEM licensing costs, feel free to schedule a demo.

Similar Posts

Augmenting Microsoft Sentinel SIEM: The Power of Exabeam for UEBA and TDIR

Exabeam Unveils 2023 Partner of the Year Award Winners

Exabeam IRAP Assessment Completion Creates New Opportunities for Partners in Australia 




Recent Posts

What’s New in Exabeam Product Development – March 2024

Take TDIR to a Whole New Level: Achieving Security Operations Excellence

Generative AI is Reshaping Cybersecurity. Is Your Organization Prepared?

See a world-class SIEM solution in action

Most reported breaches involved lost or stolen credentials. How can you keep pace?

Exabeam delivers SOC teams industry-leading analytics, patented anomaly detection, and Smart Timelines to help teams pinpoint the actions that lead to exploits.

Whether you need a SIEM replacement, a legacy SIEM modernization with XDR, Exabeam offers advanced, modular, and cloud-delivered TDIR.

Get a demo today!