<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best siem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/405329#M91994</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;hey how's it going? I still manage a PA and billion other things but since they removed my sentinel status I don't get on her much&lt;/P&gt;</description>
    <pubDate>Thu, 06 May 2021 20:49:58 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2021-05-06T20:49:58Z</dc:date>
    <item>
      <title>Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404716#M91928</link>
      <description>&lt;P&gt;Hello all its been a long time, since they took away my sentinel role I haven't been on here much. Does anyone have a recommendation for a siem?&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 12:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404716#M91928</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-05-04T12:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404847#M91940</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;I'd say that it really depends on what you are looking to use it for, and how big of a budget you have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk will likely always be my go to solution due to the number of integrations that are readily available for it. The downside is that depending on the amount of data you are trying to index it can get fairly expensive. The major benefit with Splunk however is that the sheer number of plugins and integrations available for it allows you to get useful data and insight without investing a top of time or learning Splunk SPL to build proper queries.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Graylog is definitely my go to favorite lower-cost/free option. Graylog Enterprise will give you a supported instance, and the newer Graylog Illuminate option is pretty awesome and will integrate really well with your PAN equipment. If you don't have a budget to really work with, the free Graylog Open will give you a good SIEM solution that is well documented and has various integrations available for it without any cost outside of hardware.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 03:00:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404847#M91940</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-05T03:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404942#M91956</link>
      <description>&lt;P&gt;I will definitely look into graylog and have you ever heard of ossim or suricatta&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 13:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404942#M91956</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-05-05T13:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404971#M91962</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp;, sorry, can't help but what a blast from the past seeing you pop up...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 15:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/404971#M91962</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-05-05T15:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/405329#M91994</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;hey how's it going? I still manage a PA and billion other things but since they removed my sentinel status I don't get on her much&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 20:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/405329#M91994</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2021-05-06T20:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best siem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/405435#M92003</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp;, yes all is well, been very busy as our home worker count went from 2.5k to almost 8k overnight with the Covid stuff...&amp;nbsp; &amp;nbsp;not on here as much myself as most posts now are way beyond my tech ability, there are some helpful people on here...&amp;nbsp; &amp;nbsp;I do find it quite amusing that we pay tens of thousands of pounds to our support PA partner and they just seem to send back stuff that I already posted a while back...&amp;nbsp; &amp;nbsp;still if it all ran smoothly... I would be out of a job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You take care..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 09:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-siem/m-p/405435#M92003</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-05-07T09:00:46Z</dc:date>
    </item>
  </channel>
</rss>

