{"id":1490,"date":"2018-05-03T16:26:13","date_gmt":"2018-05-03T20:26:13","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=1490"},"modified":"2018-05-07T11:36:37","modified_gmt":"2018-05-07T15:36:37","slug":"next-gen-siem-aisiem-gary-southwell-seceon","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/","title":{"rendered":"What is Next-Gen SIEM with Gary Southwell of CSPi"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-484\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg\" alt=\"next-gen SIEM\" width=\"850\" height=\"350\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg 850w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-300x124.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-768x316.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-800x329.jpg 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-600x247.jpg 600w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-180x74.jpg 180w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security-400x165.jpg 400w\" sizes=\"(max-width: 850px) 100vw, 850px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/reflection-2017-gartner-magic-quadrant-siem-solutions\/\" target=\"_blank\" rel=\"noopener\">SIEM<\/a> is a broad and complex category, just as much as its cybersecurity cousins endpoint security and identity and access management. Yet while next-gen innovations in endpoint security and IAM receive a noticeable amount of attention from cybersecurity experts, next-gen SIEM solutions don\u2019t receive the same press.<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Why is that? And what does <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/cloud-security-siem-eye-sky\/\" target=\"_blank\" rel=\"noopener\">next-gen SIEM<\/a> even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider <\/span><a href=\"https:\/\/www.seceon.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Seceon<\/span><\/a>\u00a0and current GM of <a href=\"https:\/\/www.cspi.com\/\" target=\"_blank\" rel=\"noopener\">CSPi<\/a><span style=\"font-weight: 400\">. Here\u2019s our conversation, edited slightly for readability: \u00a0\u00a0\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Solutions Review: How do you define the traditional SIEM solution? What makes it traditional?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Gary Southwell: Traditional SIEM solutions focus on collecting and indexing log outputs from applications and devices. \u00a0These are used to search and find particular log details\u2014such as \u201cfor this device, search and display all logs for this particular day.\u201d These processes often generate 10s to 100s of pages of information, more\u2014possibly up to 1000 pages\u2014if there is something amiss with the device. \u00a0SIEM solutions, therefore, allow additional filter parameters to help refine searches\u2014such as \u201cthis device at this precise time,\u201d or \u201cfor these types of log event outputs.\u201d Typically, these solutions require high levels of expertise from the end-user to get filters correct.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">SIEMs can correlate the logs from many sources when searching on a device\u2014say by IP address. It\u2019s great for forensic deep dives for auditing compliance event reporting for instance.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Some SIEMs will also take in network data but tend to have difficulty using such information effectively\u2014it can generate a tidal wave of flow data for a device, adding 1000s more line items in addition to the log data in a search. This is a problem, as the network provides the other half of the needed data to detect most active threats<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: By contrast, what is next-gen SIEM? What features or capabilities do these solutions have in contrast to traditional SIEM?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GS: Traditional SIEM solutions find information, and some feature analysis to help provide additional info indicating what might be happening on your network. These can include events such as \u201ccredential change logged for this user,\u201d or \u201cthis user logged in from multiple devices simultaneously\u201d.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, traditional SIEM solutions tend to provide such info with every bit of collected data around the user or device in question \u2013 so you may see hundreds to thousands of lines of info, which you must sort through to figure out what exactly is happening. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">They also take a long time to get data out (often days) in busy environments unless you put in tens of dedicated high-end computing devices, which can make the solution all that more complicated to deploy and support. \u00a0This is a problem: loss of credentials is the number one cause of critical data loss and most attackers are in and out with the data they want on the same day as the credentials were lost. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In contrast, a next-gen SIEM solution will ingest both log and flow data. It uses threat models to determine the threats rather than relying on a human brain. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">These are complicated models that can detect and match threat behaviors to a particular type of threat such as a DDoS attack versus a brute force attack, malware infection, APTs loss of credentials, or insider attack. \u00a0It will leverage but not rely on the proper use of <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/machine-learning-siem-security-analytics-know\/\" target=\"_blank\" rel=\"noopener\">machine learning<\/a> to pick out behaviors that are not normal for the device, application, or user, and correlate these events with other rule-triggers that can be correlated into a threat model. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Once a match is found, an alert is built that continues to aggregate individual threat behaviors under a single line alert on the user interface\u2014this is versus hundreds to thousands of lines generated by a SIEM solution before hand-filtering. \u00a0Better yet, this one line tells you the type of threat and the devices and\/or user involved, and what to do about it.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The best next-gen SIEM solutions will be architected to detect the threats within minutes of them becoming active. This includes stopping brute force attacks, compromised credentials, and insider threats before critical data is accessed. Legacy SIEMs can\u2019t promise this.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Next-gen SIEM stops the threats as they are detected automatically, with no human operator involved. Using AI techniques, they take specific appropriate actions to stop each type of threat such as writing filters to firewalls to stop malware, APTs, ransomware, DDoS attacks, data exfiltration, etc. \u00a0It can also connect to the directories as an admin and disable a particular user\u2019s credentials to stop critical device data access. These actions are specific to the type of threat and the progression of the threat, taking appropriate action before critical harm to the enterprise.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: Why hasn\u2019t next-gen SIEM seen as much publicity as, say, next-gen endpoint security? Where is the conversation surrounding it?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GS: First, there are very few platforms that do all these functions. \u00a0Gartner is just in the midst of recognizing the category in 2018. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">It\u2019s also a totally different mindset that flies counter to what the security culture has built processes around to date i.e. the need for highly skilled threat hunters to dig through piles of data to find problems, often taking hours to days. Next-gen SIEM\u2019s approach makes that work fully automated. It shakes up the status quo with a whole different methodology and set of work processes. These smart people can be freed up to stop such threats from reoccurring or occurring in the first place. \u00a0These can represent big changes in day-to-day cybersecurity work.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Further, next-gen SIEM solutions\u00a0are being rapidly adopted by a large market segment nobody is tracking very well: managed security services providers (<a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/4-questions-on-managed-security-services-providers-with-tyler-hardison-of-redhawk\/\" target=\"_blank\" rel=\"noopener\">MSSPs<\/a>). \u00a0They realize this solution allows them to profitably offer threat detection and containment services.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>SR: How you foresee next-gen SIEM adoption? What will motivate enterprises to look at next-gen SIEM more closely?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">GS: Next-gen SIEM is a broad category and most are a simple evolution of existing SIEM capacities, adding more functions from other product types under the one platform such as vulnerability screening. These solutions are seeing slow but steady adoption for large enterprises and governments.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Next-gen SIEM represents a brand new concept to the industry, but we expect a groundswell of adoption over the next 24 months. In many cases, it will show up in powerful new MSSPs\u2019 threat detection and containment services, so it may be masked. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">These solutions will have broad appeal to the 90% of enterprises that only have firewalls and some sort of legacy endpoint security solution which can be ineffective at quickly or accurately detecting most of the threats discussed above. However, larger enterprises are realizing what cybersecurity platforms they have do not scale and are completely ineffective. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Equifax was a watershed event. This was the first incident where mass firings took place for complete reliance on ineffective processes that are embraced by many today as best practices. \u00a0There were 1,400 breaches like Equifax in the US alone last year. Therefore we expect a more open-minded outlook for a more effective way\u2014at least for those enterprises that are housing valuable information that needs protection.<\/span><\/p>\n<p style=\"text-align: justify\"><b>Thanks again to Gary Southwell of <\/b><a href=\"https:\/\/www.seceon.com\/\" target=\"_blank\" rel=\"noopener\"><b><span style=\"color: #3366ff\">Seceon<\/span><\/b><\/a><strong>\u00a0and <a href=\"https:\/\/www.cspi.com\/\">CSPi<\/a><\/strong><b>\u00a0for his time and expertise!<\/b><\/p>\n<p><span style=\"font-weight: 400\"><br \/>Widget not in any sidebars<br \/>\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SIEM is a broad and complex category, just as much as its cybersecurity cousins endpoint security and identity and access management. Yet while next-gen innovations in endpoint security and IAM receive a noticeable amount of attention from cybersecurity experts, next-gen SIEM solutions don\u2019t receive the same press. Why is that? And what does next-gen SIEM [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551],"tags":[95,145,86,199,21,22],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What is Next-Gen SIEM with Gary Southwell of Seceon<\/title>\n<meta name=\"description\" content=\"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Next-Gen SIEM with Gary Southwell of Seceon\" \/>\n<meta property=\"og:description\" content=\"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-03T20:26:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-05-07T15:36:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"850\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/\",\"name\":\"What is Next-Gen SIEM with Gary Southwell of Seceon\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg\",\"datePublished\":\"2018-05-03T20:26:13+00:00\",\"dateModified\":\"2018-05-07T15:36:37+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg\",\"width\":850,\"height\":350,\"caption\":\"What Makes Next-Generation SIEM So Essential?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is Next-Gen SIEM with Gary Southwell of CSPi\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is Next-Gen SIEM with Gary Southwell of Seceon","description":"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/","og_locale":"en_US","og_type":"article","og_title":"What is Next-Gen SIEM with Gary Southwell of Seceon","og_description":"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2018-05-03T20:26:13+00:00","article_modified_time":"2018-05-07T15:36:37+00:00","og_image":[{"width":850,"height":350,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg","type":"image\/jpeg"}],"author":"Ben Canner","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/","name":"What is Next-Gen SIEM with Gary Southwell of Seceon","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg","datePublished":"2018-05-03T20:26:13+00:00","dateModified":"2018-05-07T15:36:37+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"What does next-gen SIEM even look like? For more information, we spoke to Gary Southwell, Co-Founder of SIEM solution provider Seceon.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2016\/06\/security.jpg","width":850,"height":350,"caption":"What Makes Next-Generation SIEM So Essential?"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/next-gen-siem-aisiem-gary-southwell-seceon\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"What is Next-Gen SIEM with Gary Southwell of CSPi"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/1490"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=1490"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/1490\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/484"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=1490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=1490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=1490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}