Core Netwars Continuous Hones New Skills - FREE with OnDemand Training for One Week Only!

London November 2019

London, United Kingdom | Mon, Nov 11 - Sat, Nov 16, 2019
This event is over,
but there are more training opportunities.

A Walk Through Logs Hell

  • Xavier Mertens
  • Tuesday, November 12th, 6:00pm - 7:00pm

Once upon a time, an ogre called ‚SIEM" was invented‚¶ Today, if your organization does not have a SIEM, you look like the "Little Tom Thumb‚ among your peers. During infosec meetups, many people like to brag about the power of the monster they deployed: ‚We can ingest 5K events per second!‚ or ‚We index 3TB a day!‚. That looks indeed nice but does not impress me much. Are you sure that you can still find the needle from a haystack? Being involved with such technologies and environments for a while, I had the opportunity to face many situations where the ogre SIEM was not able to return interesting data due to mis-configurations, topology changes, lack (or absence) of logs, wrong normalization and many more... Managing logs and events is not an easy job. This presentation will tell you some nightmare stories that you could also face in your organizations. And, of course, some ideas to prevent them.

Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
Tuesday, November 12
Session Speaker Time Type
A Walk Through Logs Hell Xavier Mertens Tuesday, November 12th, 6:00pm - 7:00pm SANS@Night
Doing Security Backwards: I Got 99 Tools, but Time Ain‚t One Jon Gorenflo Tuesday, November 12th, 7:00pm - 8:00pm SANS@Night