Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    LogRhythm Advances NextGen SIEM Security Platform With SOAR Features

    Written by

    Sean Michael Kerner
    Published October 30, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Some organizations might think of Security Information and Event Management (SIEM) technology as only being concerned with log collection for security, but that’s not what LogRhythm’s NextGen SIEM system is all about.

      LogRhythm announced its 7.4 release on Oct. 30, enhancing the company’s NextGen SIEM platform with advanced Security Orchestration, Automation and Response (SOAR) capabilities. Among the new features in the LogRhythm update are case playbooks for organizing a workflow for security events. Automated response actions have also been added to the platform as well as Security Operations Center (SOC) metrics.

      “In the 7.4 release we’ve furthered our feature set for SOAR with the introduction of more formalized procedural playbooks that bring along a specific set of tasks and procedures for common types of issues, such as a ransomware and phishing,” Chris Petersen, co-founder and chief product and technology officer at LogRhythm, told eWEEK. “These playbooks can be pulled into the investigation, and then all the procedures, tasks and deadlines come along with it automatically to ensure a highly consistent response by the security operations team.”

      The LogRhythm 7.4 update also integrates additional automated response auctions into the platform. LogRhythm has a framework called Smart Response, which enables different plugins that can provide remediation and response actions. Plugins include threat intelligence lookups as well as remediation actions such as disabling accounts, quarantining endpoints and killing sessions.

      “We keep adding plugins into this framework that allow us to integrate with a wide variety of third-party technologies,” Petersen said. “We’ve added about 45 additional automated actions to our library.”

      Metrics are also getting a boost in the new update. Petersen said that there are now deeper metrics in the platform that enable organizations to measure the time to triage and qualify security alarms, as well as how much time it takes to investigate threats.

      “Our goal here is to really arm the CISO or SOC manager with very detailed intelligence into their security operations team with metrics where they can understand where they are trending in terms of ability to detect and respond to threats,” he said.

      Thoma Bravo

      This has been an eventful year for LogRhythm, which was acquired by private equity firm Thoma Bravo on July 2. 

      Peterson said that since the acquisition, there has not been a whole lot of change at LogRhythm in terms of day-to-day operations. He did note that the Thoma Bravo team brings management experience that is helpful for accelerating and growing the LogRhythm business

      “Thoma Bravo brings a lot of expertise to the management team to  just help us continue to realize the goals of the business and the mission of the company,” Peterson said. “Which is to be a platform leader in next-gen SIEM.”

      SIEM vs SOAR

      While the SIEM market was once only about log files, Peterson said that the traditional view of SIEM is very narrow in terms of what is actually needed by organizations.

      “The fundamental and purpose for SIEM in the first place was to enable the detection and response to threats,” Peterson said. “The fundamental mission of SIEM is to correlate data, identify the right alarms and get teams to respond.”

      Peterson added that in the modern era getting teams to respond faster involves orchestration and automation of as many actions as possible. The move to integrate SOAR capabilities into SIEM is seen by Peterson as an evolution of what SIEM should provide.

      “One of the challenges with SOAR being a separate technology that is put on top of a legacy SIEM is you have two different pieces of software that need to be integrated through APIs and need to have some kind of a integrated workflow,” he explained. 

      Having two separate technologies, rather than integrating SOAR into SIEM, slows down the process and introduces additional complexity, according to Peterson. The LogRhythm model has a unified user interface that enables a user to move through the SIEM components with correlation and analytics and then move directly into remediation execution actions.

      “You’re not having to pivot between two different pieces of software to execute a workflow that really needs to be done cohesively,” Petersen said. “Fundamentally, what we’re trying to achieve here is speed of throughput and speed through the SOC.”

      Looking forward, Petersen said that LogRhythm will be looking to apply additional machine learning capabilities into the platform for behavioral profiling and predictive analytics.

      “Next year you’ll see us make more announcements around SOAR and around our UEBA [User and Entity Behavior Analytics) product as well,” Petersen said. “We will be talking about a new product that is focused more on the network detection side of things.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×