Hey everyone! 👋 I’m pretty new to the whole security operations side of things, coming from a sales ops background where I mostly live in Salesforce reports. My company is growing fast and we’ve shifted to a fully remote workforce of around 1000 people. Leadership is now asking me to help evaluate SIEM tools, and honestly, I’m feeling a bit out of my depth.
I’ve been reading a ton of reviews, but a lot of them seem very… generic? I’d love to hear from teams who are actually using these tools in a similar environment. What works when your users are all over the place, logging in from personal devices and home networks? We’re especially concerned about detecting weird login patterns and potential data exfiltration without being able to monitor a traditional corporate network.
From my CRM world, I know that data quality and clear workflows are everything. So I'm curious:
- How do these tools handle the data ingestion from so many distributed endpoints and cloud apps?
- Is the alerting actually actionable for a team that might not have a huge dedicated security analyst bench?
- How steep is the learning curve for setting up and maintaining useful reports and dashboards?
I’ve seen Elastic Security, Splunk, and a few others mentioned constantly, but I’m really looking for “it just works” experiences rather than a list of features. Any real-world insights or pitfalls you’ve encountered would be incredibly helpful!