Friday SIEM post is here. This week I talk about SIEM readiness, or just call it health checks. Who actually owns it?
What I refer to as readiness is monitoring the health of your pipeline. Are the log sources you ingest in good shape? Are your detections in good shape?
I was thinking about a topic for this week and this came to mind. Then I went back through my experience over the years, just to realize the process was almost always broken.
Why I say this: SIEM is usually managed by your engineering team. They implement, fine tune and configure the platform (in some cases even external contractors). They set up the log sources, schemas etc. And they monitor if the data flows as expected, no sharp drops or spikes.
Then it falls on the detection engineering team, or even SOC analysts, to say when something is broken.
Because when you build detections you realize the data is missing key fields or is not parsed properly.
Or as a SOC analyst you see alerts with minimal context, or rules that stopped firing a long time ago. You tell detection eng, they go back to SIEM eng.
In other words, your pipeline can be broken for a very long time and no one will know. Because everyone is too busy doing triage, or building detections for the latest security article that doesn't affect you at all, but you want to show you are covered.
Is it just my experience, or others noticed this problem let's say even trend?
Originally posted on LinkedIn on 12 June 2026.
Read the original post and the comments.


