Forum
9

Implementing SIEM for my small size company

asked by a8hda 1 month ago

Hello i have a few Windows and Linux servers and a logging server where i receive the logs of all of them, i want to improve this solution into a SIEM. i already tried WAZUH when i was student, i want to try Graylog or ELK, which one is recommended and simple to implement ? if there is any recommendations to improve my solution i'am all ears

4 answers

Sign in to answer.
shadepl 18 points 1 month ago

if you already know wazuh why change

vivida (David) 11 points 1 month ago

Seconding that. "I used it as a student" is a much better position than "I read good things about it".

ELK is not simple to implement. It is simple to start and then it is your second job. Graylog is friendlier but you are still running Elasticsearch underneath either way.

What is actually missing from what you have now? If it is search, Graylog helps. If it is alerting and correlation, stay where you are and spend the time on rules instead.

cclondon 6 points 1 month ago

How many servers is "a few"? Under about 20 the answer is usually different than over 20.

a8hda 3 points 29 days ago

12 right now, maybe 20 by end of year. Mostly web servers and 2 DCs.

Guidelines Newest Search Back to Trunc