Cribl: The Stream Life

Cribl: The Stream Life

Download on the App Store

Cribl: The Stream Life episodes

  • Modernize Your SIEM Architecture

    In this Livestream conversation, I spoke with John Alves from CyberOne Security about the struggles teams face in modernizing a SIEM, controlling costs, and extracting optimal value from their systems. We delve into the issues around single system-of-analysis solutions that attempt to solve detection and analytics use cases within the same tool. We explored the strategic limitations of this type of security architecture, presenting alternative options for effectively mixing and matching data platforms. Be sure to watch the full conversation to get on the path toward achieving the optimal combination of data management and cost control capabilities.

    If your security architecture is centered around a SIEM that houses all your security and operational data, it's time for an upgrade. Data quantities, cyber attacks, and regulatory requirements are all on the rise, so having a single destination for your data leaves too much room for vulnerabilities. Until recently, buying a SIEM meant deploying its agents, putting all your data into it, and going on your merry way. You were almost 100% confined to that one framework — if you wanted to use UEBA, your vendor or one of their partners provided it. Operating outside your SIEM or bringing in third-party vendors was very limited.

    Observability Pipelines to the Rescue

    About five years ago, the concept of an observability pipeline emerged, allowing organizations to funnel their observability and security data through a consistent data plane. The idea of controlling where your data gets stored was born, and vendor-neutral considerations began gaining popularity. Admins can now make copies of events for their SIEM, data lake, UEBA solution, or someone else's data lake — easily turning one event into four events that power different parts of their security stack. By moving data into a data lake instead, admins can analyze data and build dashboards for operations teams without bloating their ingest. Teams have more choice and control over their data than ever before, so they can consider their specific needs when building out their infrastructure.

    The Benefits of a Data Security Lake

    During our discussion, John mentioned how this flexibility is no longer a wish-list item for his clients, but a necessity. As the industry transitions to cloud infrastructure and cloud-based computing, organizations require vendor-neutral data that supports their scalability efforts. There are a host of benefits you get from modernizing your security architecture.

    Reduced License Costs

    Routing data that isn't needed for security to object storage is one of the best ways to reduce SIEM license costs. Ingest costs go down, and you avoid the upsell for archive data — around a 4- 8x markup — as opposed to using your own object storage or your SIEM cloud platforms archive. You can also store it in a vendor-neutral format, giving you enormous flexibility that you wouldn't get otherwise. We recently worked with a developer team and their debug logs, routing them to a lower-cost S3 bucket instead of their SIEM. All we had to do was create a rule in Cribl Stream to route them to the data lake, and now they're available to be restored whenever necessary. This is just one example of many where we can set customers up to meet their simultaneous need for availability but lower cost and overhead.

    Increasing Security While Decreasing Engineering Time

    When you can reduce your SIEM license costs, you no longer have to choose which data sources you can afford to collect. By removing the constraints for engineers that come from not having the raw data when needed, security teams can focus on security and not just moving data around. No more time spent on tasks like going out to a server to manually zip up and pull in logs. The result? Better detections, analytics, and security.

    Shared Data Within the Organization

    Each team has a different use case for the data the organization collects — having different pipelines to transform and send data to different sources is invaluable. Putting firewall, threat, traffic, and systems logs into a single destination is a great way to bloat your ingest. And not all logs from a single data source are security relevant. Routing some of them into a storage account or data lake will not only save on ingestion costs and create less noise for security teams, but you can also give access to relevant logs to your infrastructure, firewall, and other teams. Route your threat logs straight into the SIM, but send traffic and other logs straight into the data lake for your infrastructure network team.

    Compliance With Retention Requirements

    Another benefit of keeping raw copies of data is complying with retention requirements. If you're manipulating data before it goes into your SIEM, then you're not adhering to some necessary standards. Transform events to get what you need for your SIEM, but keep unmanipulated, raw copies in your data lake. Your IR or legal counsel can control forensic copies.

    Meet Cyber Insurance Requirements

    As insurance companies get more sophisticated and start hiring engineers as auditors, they'll dive deeper into your architecture than before. They'll ensure you have a SIEM in place but also check to see if you're putting the right data in and using it appropriately. Government auditors will want to see all your data sources and detections. They'll be ready to write findings if you're not following best practices. The prevalence of bad data or an overwhelming amount of data leads to various issues with detection, and drives costs higher and higher. It is extremely common to witness a year-over-year cost increase of up to 35%, which is clearly unsustainable. Watch the full livestream to hear John and I talk about alternative options for your SIEM platform, so you can be empowered to re-architect your data strategy. With the right strategies, SIEM platform challenges can be overcome, and we're here to help as you embark on this transformative journey.

    38 min
  • Solving Data Challenges with Adam Hogan from CrowdStrike

    In this episode of The Stream Life Podcast which was recorded after our announcement earlier this year, Adam Hogan from CrowdStrike joins the show to talk about the current challenges customers have with their data and the potential solutions.

    Resources
    • Future-Proof Your Observability Strategy With CrowdStrike and Cribl
    • Cribl Wins 2023 CrowdStrike Ecosystem Innovator of the Year Award

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    24 min
  • Hackers Aren't Hacking Into Your Network -- They're Just Logging In

    In this episode of Cybersecurity Awareness Month-themed episode of The Stream Life Podcast, Nick Heudecker and Jackie McGuire talk about the state of cybersecurity, "the people problem, and why hackers aren't hacking into your network -- they're just logging in.

    Resources
    • Security Teams Are Struggling, and Cribl Is Here to Help

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    18 min
  • Unpacking the Hype: Navigating the Complexities of Advanced Data Analytics in Cybersecurity

    The cybersecurity industry is experiencing an explosion of innovative tools designed to tackle complex security challenges. However, the hype surrounding these tools has outpaced their actual capabilities, leading many teams to struggle with complexity and extracting value from their investment. In this conversation with Optiv's Randy Lariar, we explore the potential and dangers of bringing advanced data analytics and artificial intelligence tools to the cybersecurity space.

    26 min
  • The Gartner Hype Cycle for Observability and Monitoring

    In this episode of The Stream Life Podcast, Nick Heudecker comes back on the show to talk about the recently released Gartner Hype Cycle for Observability and Monitoring.

    Resources
    • What is observability?
    • Hype Cycle for Monitoring and Observability, 2023

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    23 min
  • Reference Architecture Series: Scaling Syslog

    In this live stream, Cribl's Ed Bailey and Ahmed Kira go into more detail about the Cribl Stream Reference Architecture, with a focus on scaling syslog. They share a few use cases, some guidelines for handling high-volume UDP and TCP syslog traffic, and talk about the pros and cons of some of the different approaches to tackling this challenge.

    34 min
  • What are Telemetry Pipelines?

    In this episode of The Stream Life Podcast, Nick Heudecker joins the show to dive into an emerging buzzword in the IT and security industries: Telemetry pipelines. Nick explains what it is, why it's important, and why it's becoming popular in 2023.

    Resources
    • Telemetry 101

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    20 min
  • Cribl and Exabeam Aim to Accelerate Technology Adoption for Customers

    In this episode of The Stream Life Podcast, Cribl's Desi Gavis-Hughson and Exabeam's Chris Stewart join the show to talk about the big news out of Black Hat 2023: Cribl and Exabeam's strategic partnership!

    Resources
    • Press Release
    • Blog
    • Cribl's solutions with Exabeam

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    26 min
  • Cribl's Enhanced Authorization Support

    In this episode of The Stream Life Podcast, Nick Tankersley joins the show to talk in-depth about the upgraded authorization support released in Cribl's 4.2 release. Cribl's new authorization support enhances security by giving you control over who has permissions and privileges to access Cribl products, capabilities, and resources. This ensures users only see and access what they're permitted to based on their assigned role. This level of authorization helps safeguard organizations against potential security threats.

    Resources
    • Turning Up the Heat: Cribl's Summer Product Launch
    • Different Access for Different Roles: Cribl's New Authorization Support for Enhanced Security
    • Members and Permissions - Cribl Docs

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    18 min
  • What's New With Cribl Stream, Edge, and Search? - Summer Launch

    In this episode of The Stream Life Podcast, Perry Correll and Nick Tankersley join the show to talk about all the latest enhancements coming to Cribl Stream, Cribl Edge, and Cribl Search!

    Resources
    • Turning Up the Heat: Cribl's Summer Product Launch

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    38 min

About Cribl: The Stream Life

From the publisher's feed

Welcome to Cribl: The Stream Life, a podcast for IT pros trying to take control of their observability data with a no-compromise approach. With each episode, our hosts will cover the latest insights,…