Thursday, August 01, 2013

Monthly Blog Round-Up – July 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month:
  1. Why No Open Source SIEM, EVER?” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge.
  2. Simple Log Review Checklist Released!” is often at the top of this list – the checklist is still a very useful tool for many people. “On Free Log Management Tools” is a companion to the checklist (updated version)
  3. Top 10 Criteria for a SIEM?” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.
  4. On Choosing SIEM” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.
  5. “SIEM Bloggables” has one possible view on higher-level SIEM use cases and basic functionality, and a quick discussion of SIEM user types (circa 2009)
  6. Finally, my classic PCI DSS Log Review series is popular as well. They outlined log review approach, useful for building log review processes and procedures, whether regulatory or not.
In addition, I’d like to draw your attention to a few recent posts from my Gartner blog:
Current research on incident response:

Current research on endpoint detection and investigation tools (ETDR):


Miscellaneous fun posts:

(see my published Gartner research here)

Also see my past monthly and annual “Top Popular Blog Posts” – 2007, 2008, 2009, 2010, 2011, 2012.

Disclaimer: all content at SecurityWarrior blog was written before I joined Gartner on Aug 1, 2011 and is solely my personal view at the time of writing. For my current security blogging, go here.

P.S. Please send congrats with my 2nd anniversary @ Gartner! Smile

Previous post in this endless series:

Dr Anton Chuvakin