DiscoverCloud Security Podcast by GoogleEP250 The End of "Collect Everything"? Moving from Centralization to Data Access?
EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

Update: 2025-11-03
Share

Description

Guest:

Topics:

  • Are we really coming  to "access to security data" and away from "centralizing the data"?
  • How to detect without the same storage for all logs?
  • Is data pipeline a part of SIEM or is it standalone? Will this just collapse into SIEM soon?
  • Tell us about the issues with log pipelines in the past?
  • What about enrichment? Why do it in a pipeline, and not in a SIEM?
  • We are unable to share enough practices between security teams. How are we fixing it? Is pipelines part of the answer?
  • Do you have a piece of advice for people who want to do more than save on their SIEM costs?

Resources:

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

Anton A Chuvakin