{"id":3213,"date":"2020-10-30T16:12:12","date_gmt":"2020-10-30T20:12:12","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=3213"},"modified":"2020-10-30T16:12:12","modified_gmt":"2020-10-30T20:12:12","slug":"where-should-you-collect-your-logs-for-siem-during-covid","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/","title":{"rendered":"Where Should You Collect Your Logs for SIEM During COVID?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2358\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg\" alt=\"TWhere Should You Collect Your Logs for SIEM During COVID?\" width=\"800\" height=\"450\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD-300x169.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD-768x432.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD-480x270.jpg 480w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD-144x81.jpg 144w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD-320x180.jpg 320w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">One of the perpetual challenges of business SIEM involves where you should collect your logs. This question becomes amplified in the shift to remote work mandated by COVID-19.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Here are the basics of the problem: SIEM collects logs from across the IT environment and aggregates them. This forms the cornerstone of SIEM as a cybersecurity solution; these logs become normalized and analyzed to discover security events and generate alerts.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\"><div class=\"box box3\">ALERT: Our <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-buyers-guide-security-information-and-event-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">Buyer\u2019s Guide for SIEM<\/a> helps you evaluate the best solutions for your business use case and features profiles of the leading profiles, as well as a category overview of the marketplace and Bottom Line Analysis.<\/div><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, trying to draw logs from everywhere in the IT environment all at once can create more problems than it solves. First, trying to draw from everywhere at once can actually cause configuration rule issues and data pile-up; this can overwhelm the solution. Second, too many logs can cause more false-positive alerts, which lead to burnout and buried legitimate leads.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">On the surface, this might seem like an easy problem to solve. All you need to do, in theory, is to be more selective about the digital locations you draw logs from and keep a close eye on those configuration rules. Yet the COVID-19 pandemic, and the shift to remote work en masse, has thrown that calculation out of balance.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In other words, where do you collect logs from during COVID when the entire business exists remotely?\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Here are a few pointers. Use user and entity behavior analysis (UEBA) starting with the most privileged users; their behaviors and credentials have the largest impact on your network, so you should keep a closer eye on them. Also, make sure your sensitive data stays centralized so you can monitor it closely; use Data Loss Prevention capabilities (DLP) to prevent users from uploading data to unauthorized locations such as public cloud databases. That way, even though users work remotely, your silos stay centralized for log management.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Finally, make sure your configuration rules for security events detected by the solution recognize the current circumstances. Logging in remotely, for example, might trigger an alert prior to COVID, but now must be recognized as a normal part of the business day.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">You can learn more in our <a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/siem-buyers-guide-security-information-and-event-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">SIEM Buyer\u2019s Guide<\/a>.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\"><br \/>Widget not in any sidebars<br \/><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the perpetual challenges of business SIEM involves where you should collect your logs. This question becomes amplified in the shift to remote work mandated by COVID-19.\u00a0 Here are the basics of the problem: SIEM collects logs from across the IT environment and aggregates them. This forms the cornerstone of SIEM as a cybersecurity [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2358,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1,3],"tags":[1310,95,112,86,295,212,48,21,57,22],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Where Should You Collect Your Logs for SIEM During COVID?<\/title>\n<meta name=\"description\" content=\"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Where Should You Collect Your Logs for SIEM During COVID?\" \/>\n<meta property=\"og:description\" content=\"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-30T20:12:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Canner\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/\",\"name\":\"Where Should You Collect Your Logs for SIEM During COVID?\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg\",\"datePublished\":\"2020-10-30T20:12:12+00:00\",\"dateModified\":\"2020-10-30T20:12:12+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg\",\"width\":800,\"height\":450,\"caption\":\"Expert 2021 Cybersecurity Predictions (Insight Jam Roundup)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Where Should You Collect Your Logs for SIEM During COVID?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Where Should You Collect Your Logs for SIEM During COVID?","description":"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/","og_locale":"en_US","og_type":"article","og_title":"Where Should You Collect Your Logs for SIEM During COVID?","og_description":"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2020-10-30T20:12:12+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg","type":"image\/jpeg"}],"author":"Ben Canner","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/","name":"Where Should You Collect Your Logs for SIEM During COVID?","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg","datePublished":"2020-10-30T20:12:12+00:00","dateModified":"2020-10-30T20:12:12+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"One of the perpetual challenges of business SIEM involves where you should collect your logs, especially in the shift to remote work mandated by COVID-19.\u00a0","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2018\/12\/The-Top-6-SIEM-Vendors-to-Watch-in-2019-By-Solutions-Review-MOD.jpg","width":800,"height":450,"caption":"Expert 2021 Cybersecurity Predictions (Insight Jam Roundup)"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/where-should-you-collect-your-logs-for-siem-during-covid\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"Where Should You Collect Your Logs for SIEM During COVID?"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/3213"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=3213"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/3213\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/2358"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=3213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=3213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=3213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}