It is a new and upcoming siem but has the potential to become next big thing.
What do you like best about the product?
Its detection capability, integration options, outbound webhook, contextual data, Background queries, parsing rules etc etc
What do you dislike about the product?
Management of platform is very time consuming.
automation is not there.
if we want to map 120 alerts to new subsystem there is no one click option. have to do it manually.
Their alerts in the extension pack is very broad. once we onboard the extension alerts, we finetune it and in the next update of the extension remove all the finetune we have done in the search query.
automation is not there.
if we want to map 120 alerts to new subsystem there is no one click option. have to do it manually.
Their alerts in the extension pack is very broad. once we onboard the extension alerts, we finetune it and in the next update of the extension remove all the finetune we have done in the search query.
What problems is the product solving and how is that benefiting you?
Detection Engineering and Response.