Hi everyone! I'm new to the whole SIEM/SOAR space, but my team is being asked to help evaluate options. We're a small dev team that also handles our own cloud infrastructure security.
We're looking at Chronicle and Sumo Logic. Our main needs are:
- Good visibility into GCP logs (we're mostly there).
- Not a huge time sink to set up and maintain.
- Ability to create some basic automated alerts for weird activity.
Budget is a factor, but so is not drowning in complexity. For those who've used both, which felt more... approachable for developers who aren't full-time security people? I'm worried about buying a tool that needs a dedicated analyst to run it.
The Sumo Logic dev-focused logging seems easier to grasp at first glance, but Chronicle's native GCP integration is tempting. Any real-world experiences jumping from one to the other?