{"id":2194,"date":"2018-10-02T15:27:33","date_gmt":"2018-10-02T19:27:33","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=2194"},"modified":"2018-10-05T12:10:55","modified_gmt":"2018-10-05T16:10:55","slug":"no-rules-siem-solutions-avi-chesla-empow","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/","title":{"rendered":"No-Rules SIEM Solutions with Avi Chesla of empow"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1387\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg\" alt=\"No-Rules SIEM Solutions with Avi Chesla of empow\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod-540x270.jpg 540w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod-162x81.jpg 162w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Is there another way to deploy, manage, and maintain SIEM solutions? <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">It\u2019s a question more and more enterprises are asking as threat detection becomes the Archstone of modern cybersecurity platforms. To learn more, we spoke with Avi Chesla, Founder and CTO of SIEM solution provider <\/span><a href=\"https:\/\/www.empowcybersecurity.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">empow<\/span><\/a><span style=\"font-weight: 400\">, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a href=\"https:\/\/logrhythm.com\/forrester-wave-security-analytics-analyst-report-2018\/?utm_source=Solutions-Review&amp;utm_medium=cpc&amp;utm_campaign=Solutions-Review&amp;AdGroup=&amp;utm_program=NAcpc1&amp;utm_content=C-Download-Now&amp;utm_region=NA&amp;utm_language=en\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/10\/PM_Forrester_Wave_Display_C.jpg\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<h4 style=\"text-align: justify\"><b>Solutions Review: In our preliminary communications, you mentioned your concerns about the \u201cbig rules epidemic\u201d in modern SIEM solutions. Can you explain what you mean by this? What caused this epidemic? And how does it affect enterprises\u2019 security?<\/b><\/h4>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Avi Chesla: The original promise of SIEMs, more than 15 years ago, was seductive. If you follow their evolution, however, you see how the security landscape evolved in a way that made the original promise of those first-generation SIEMs difficult to achieve: \u00a0\u00a0<\/span><\/p>\n<ul style=\"text-align: justify\">\n<li><span style=\"font-weight: 400\"> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0SIEM began as a centralized log repository and retention tool responsible for consolidating data and \u201cnormalizing\u201d it for better visibility.<\/span><\/li>\n<li><span style=\"font-weight: 400\"> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Immediately afterward, the need for security-alert rules arose. SIEM vendors responded with a log-correlation language that allowed it to customize alerts and flag possible incidents. <\/span><\/li>\n<li><span style=\"font-weight: 400\"> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Then came a bigger change\u2014the dot.com boom\u2014and an exploding internet dependency. Businesses became juicy hacking targets, and the frequency of attacks grew sky-high. In response, organizations deployed more and more security tools, each generating streams of alerts and information. The result? A massive big data problem that had a disastrous impact on SIEMs\u2019 effectiveness. The existential question became: \u201cHow many events per seconds (EPS) and data can the SIEM process?\u201d \u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400\"> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0SIEM vendors responded by attempting to create more robust and scalable databases, along with search engines to allow sorting and finding logs quickly. But the system was still based on the same old manual log parsers (to classify logs into security behavior categories), and static correlation rules to detect pre-defined attack sequences.<\/span><\/li>\n<li><span style=\"font-weight: 400\"> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0In this new reality, the number of rules required to cover all the attack patterns grew exponentially\u2014based on the number of logs <\/span><b>and constantly changing threat data<\/b><span style=\"font-weight: 400\">.<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Imagine being a SIEM administrator having to create and maintain thousands of rules to keep up with constantly changing cyber threat data and attack patterns\u2014talk about a thankless job!<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So here is the one critical challenge SIEM vendors ignored (including the ones currently calling themselves \u201cnext-generation\u201d SIEM): The need to create and maintain the vast array of log-parser and security-correlation rules to detect new and unknown attack sequences faster and faster than ever before.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This is the \u201cBIG RULES\u201d problem that makes SIEM a passive (rules-based) log aggregation and reporting tool, rather than an active cyber defense system. How does it affect enterprises?<\/span><\/p>\n<p style=\"text-align: justify\"><b>Too Reactive<\/b><span style=\"font-weight: 400\"> &#8211; The SIEM is a purely reactive security system that simply misses new or unknown attack sequences.<\/span><\/p>\n<p style=\"text-align: justify\"><b>Too Complex<\/b><span style=\"font-weight: 400\"> &#8211; Typical large (and even medium-sized) organizations are burdened with thousands of log-source parser and security correlation rules that are simply impossible to maintain given how fast the threat landscape is changing.<\/span><\/p>\n<p style=\"text-align: justify\"><b>Too Expensive<\/b><span style=\"font-weight: 400\"> &#8211; SIEMs require massive ongoing investment to cope with the \u201cBig Rules\u201d problem, which results in a very high total cost of ownership.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Does this mean that SIEMs are destined to disappear from the security arsenal? Absolutely not\u2014but it does mean that a new kind of SIEM needs to emerge: one that requires no human-written rules.<\/span><\/p>\n<h4 style=\"text-align: justify\"><b>SR: What is a \u201cno rules\u201d SIEM system? What does it look like?<\/b><\/h4>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">AC: The \u201cBig Rules\u201d problem can be solved by a \u201cno rules\u201d SIEM system. This type of SIEM is constructed with a stack of intelligence layers. The first (and most fundamental) layer is responsible for automatically classifying logs and data feeds into security \u201cintent\u201d &#8211; that is, separating benign activity from activity demonstrating malicious intent. The overall no-rules SIEM process looks like this:<\/span><\/p>\n<p style=\"text-align: justify\"><b>Data collection<\/b><span style=\"font-weight: 400\">: A no-rules SIEM needs to be open for use with any database for collecting structured and unstructured data, including logs, network flows, intelligence feeds, user and account activities, and more. This enables them to work with existing commercial databases and open source options, which prevents the massive cost escalations that can occur with big data projects locked into a single commercial database vendor. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><b>Intent classification<\/b><span style=\"font-weight: 400\">: A no-rules SIEM needs to be able to decipher the security intent of each collected log and data feed using machine learning (ML) and Natural Language Processing (NLP) algorithms. The algorithms emulate the actions done today by security analysts: reading logs and data feeds, seeking out relevant information from the log itself and from third-party data sources outside the organization, and identifying attack intent. This process runs continuously and automatically with virtually no human involvement, replacing the need for manual logs parsers.<\/span><\/p>\n<p style=\"text-align: justify\"><b>Auto-Correlation:<\/b><span style=\"font-weight: 400\"> Finally, a no-rules SIEM needs an analytics module that includes user\/entity behavioral analytics (UEBA), network traffic analysis (NTA), and cause-and-effect analytics engines. This module identifies cause-and-effect relationships between the collection of deciphered intents (intents that are generated by the UEBA and NTA engines, and the NLP-based data and log classification), grouping them together and creating a visual attack story. This engine also emulates human security expert processes: it decides in real-time, according to the attack intent, which investigation policies are required, and, according to the system\u2019s risk assessment capabilities, decides which proactive response policies to employ.<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n<h4 style=\"text-align: justify\"><b>SR: Are artificial intelligence and behavioral analytics sophisticated enough to allow for a no-rules SIEM platform?<\/b><\/h4>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">AC: Artificial intelligence (AI) applications have made huge progress in certain areas. Siri and Alexa, for example, use NLP and speech recognition (speech-to-text translation applications), while Watson uses mainly NLP to answer questions. These applications get smarter and smarter all the time.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Unsupervised AI applications, for example, can learn from the environment and adapt accordingly, creating new patterns on the fly. These applications study and process their environments to create new classes of behaviors. They then adapt, independently, to better execute various decision-making functions, mirroring human thinking patterns and neural structures &#8211; which is precisely what made Stephen Hawking so nervous. Some examples include applications capable of learning an individual\u2019s text message or email style, browsing behavior, and interests. Facebook and Google employ this approach to study user behaviors and adjust their results (and advertisements) accordingly.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Having said all this, AI is not yet in the stage that it can replace humans, which brings up another important point: Commercial security solutions that are deployed in production environments can never be dependent on AI\/ML only. They should include heuristics rules that wrap it (and are developed based on security domain expertise) and can filter out non-relevant results (noise and false positives) that AI\/ML algorithms can and do generate. These heuristic rules should allow control of the sensitivity of the algorithms and adjust it to various environments and business needs. A no-rules SIEM should include some level of heuristics rules to be an effective system.<\/span><\/p>\n<h4 style=\"text-align: justify\"><b>SR: Can you share some of your thoughts on the utility and role of UEBA in a typical SIEM platform? How important is it to enterprise security in the context of the modern threat landscape? \u00a0<\/b><\/h4>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">AC: In general, an integrated UEBA capability enables the SIEM to provide automated detection and adaptive response to threats <\/span><span style=\"font-weight: 400\">across the entire cyber kill chain<\/span><span style=\"font-weight: 400\">. It\u2019s important to note that UEBA does not do this on its own, but as part of a complete no-rules SIEM. User and account activity logs are important inputs for detecting attacks by insiders or external intruders who have already compromised user account credentials. Therefore, UEBA is mainly useful in the middle and late phases of the cyber kill chain, but not in the earlier stages of the attack. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A proactive, no-rules SIEM should use AI and UEBA to digest security logs and network-flow logs\u2014as well as user and account activity logs\u2014to automatically detect and respond to malicious activity across all phases of the attack life cycle, accurately. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">When UEBA is integrated into a SIEM, it should take unusual user, entity and account behavior into consideration \u2013 along with many other factors and indicators \u2013 when identifying and validating attacks. Unusual user behavior is one indicator of an attack, but not the only indicator, and by itself is not necessarily sufficient for making a clear actionable decision.<\/span><\/p>\n<h4 style=\"text-align: justify\"><b>SR: What is the next stage of SIEM\u2019s evolution, in your expert opinion?<\/b><\/h4>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">AC: It\u2019s an assembly of the following key capabilities:<\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><b>Flexible data ingestion<\/b><span style=\"font-weight: 400\"> from all log and data sources, either directly from the security infrastructure or indirectly (via intermediate open log and data storage, without requiring the development of plugins and complex parsers for new data sources).<\/span><\/li>\n<li style=\"font-weight: 400\"><b>AI-driven classification<\/b><span style=\"font-weight: 400\"> of security events, which leverages NLP on both machine- and human-readable threat intelligence from internal and external sources, to understand the intent behind each event.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Auto-correlation<\/b><span style=\"font-weight: 400\"> using cause-and-effect analytics to automatically validate and prioritize attacks and reveal the complete \u201cattack story\u201d \u2013 without requiring static correlation rules.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Adaptive orchestration<\/b><span style=\"font-weight: 400\"> using the capabilities of the existing security infrastructure to actively investigate and mitigate (block) attacks, without requiring scripts.<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><b>Thanks again to Avi Chesla of <\/b><a href=\"https:\/\/www.empowcybersecurity.com\/\" target=\"_blank\" rel=\"noopener\"><b><span style=\"color: #3366ff\">empow<\/span> <\/b><\/a><b>for his time and expertise!<\/b><\/p>\n<p style=\"text-align: justify\"><strong>Other Resources:\u00a0<\/strong><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/10-coolest-siem-security-analytics-ceo-leaders\/\" target=\"_blank\" rel=\"noopener\">The 10 Coolest SIEM and Security Analytics CEO Leaders<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/5-tips-setting-security-operations-center\/\" target=\"_blank\" rel=\"noopener\">5 Tips for Setting Up a Security Operations Center (SOC)<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/get-employees-embrace-siem-best-practices\/\" target=\"_blank\" rel=\"noopener\">Get Your Employees to Embrace SIEM Best Practices!<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/4-tips-make-data-breach-detection-easier-enterprise\/\" target=\"_blank\" rel=\"noopener\">4 Tips to Make Data Breach Detection Easier For Your Enterprise<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/dont-become-complacent-in-your-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Enterprises: Don\u2019t Become Complacent in Your Cybersecurity!<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/make-siem-solution-deployment-easier-enterprise\/\" target=\"_blank\" rel=\"noopener\">How to Make Your SIEM Solution Deployment Easier for Your Enterprise<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/comparing-the-top-siem-vendors-solutions-review\/\" target=\"_blank\" rel=\"noopener\">Comparing the Top SIEM Vendors \u2014 Solutions Review<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/ueba-prevent-insider-threats-enterprise\/\" target=\"_blank\" rel=\"noopener\">How UEBA Can Prevent Insider Threats in your Enterprise<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-vs-security-analytics-whats-difference\/\" target=\"_blank\" rel=\"noopener\">SIEM vs Security Analytics: What\u2019s the Difference?<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/risk-analytics-bridge-the-cybersecurity-talent-gap\/\" target=\"_blank\" rel=\"noopener\">Should Risk Analytics Bridge the Cybersecurity Talent Gap?<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/1122-2\/\" target=\"_blank\" rel=\"noopener\">What\u2019s Changed? The Gartner 2017 Security Information and Event Management (SIEM) Magic Quadrant<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/the-25-best-security-analytics-and-siem-platforms\/\" target=\"_blank\" rel=\"noopener\">The 25 Best Security Analytics and SIEM Platforms for 2018<\/a><\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/c-level-leaders-chopping-block-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Are C-Level Leaders on the Chopping Block over Cybersecurity?<\/a><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><br \/>Widget not in any sidebars<br \/><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Is there another way to deploy, manage, and maintain SIEM solutions? It\u2019s a question more and more enterprises are asking as threat detection becomes the Archstone of modern cybersecurity platforms. To learn more, we spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":1387,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551],"tags":[843,353,95,145,112,86,21,57,22],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>No-Rules SIEM Solutions with Avi Chesla of empow<\/title>\n<meta name=\"description\" content=\"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"No-Rules SIEM Solutions with Avi Chesla of empow\" \/>\n<meta property=\"og:description\" content=\"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2018-10-02T19:27:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-10-05T16:10:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/\",\"name\":\"No-Rules SIEM Solutions with Avi Chesla of empow\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg\",\"datePublished\":\"2018-10-02T19:27:33+00:00\",\"dateModified\":\"2018-10-05T16:10:55+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"Will SOAR Cybersecurity Replace SIEM in the Near Future?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"No-Rules SIEM Solutions with Avi Chesla of empow\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"No-Rules SIEM Solutions with Avi Chesla of empow","description":"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/","og_locale":"en_US","og_type":"article","og_title":"No-Rules SIEM Solutions with Avi Chesla of empow","og_description":"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2018-10-02T19:27:33+00:00","article_modified_time":"2018-10-05T16:10:55+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg","type":"image\/jpeg"}],"author":"Ben Canner","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/","name":"No-Rules SIEM Solutions with Avi Chesla of empow","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg","datePublished":"2018-10-02T19:27:33+00:00","dateModified":"2018-10-05T16:10:55+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"We spoke with Avi Chesla, Founder and CTO of SIEM solution provider empow, about no-rules SIEM and what it could represent for enterprises around the world. \u00a0","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/09\/Questions-mod.jpg","width":800,"height":400,"caption":"Will SOAR Cybersecurity Replace SIEM in the Near Future?"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/no-rules-siem-solutions-avi-chesla-empow\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"No-Rules SIEM Solutions with Avi Chesla of empow"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2194"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=2194"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/2194\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/1387"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=2194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=2194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=2194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}