Friday SIEM post is here, and this week we have a poll!
I ran into this question myself while building the latest capability groups on SecOps Unpacked.
Side note: we just had one of our biggest releases so far. And yes, dark theme as well, so your eyes are not burning when you are scrolling at night ๐
Back to the question. To group capabilities I had to decide where SIEM ends and where the next category starts. We had a discussion with Rafal Kitab about this and it made me think , what does people think of the SIEM now.
>> Traditional. Log correlation and detections. The SIEM most of us grew up with.
>>My single pane. The place where SOC work is done, not just where logs land. And has everything AI SOC, SOAR, all the blows and whistles.
>>SOAR by default. Automation is expected in the platform, not bought on the side.
>> AI SOC by default. Agents doing triage and investigation out of the box.
Like I said in my previous posts:
SIEM ate the SOAR, is eating AI SOC, and Agent Studios look like the next course.
Have a siemless weekend ahead!
Read the original post and the comments

