Skip to content
Notifications
Clear all

What SIEM actually works for a k8s-heavy devops environment?

1 Posts
1 Users
0 Reactions
1 Views
(@catherinew)
Estimable Member
Joined: 2 weeks ago
Posts: 103
Topic starter   [#22148]

We're moving to a microservices setup and our k8s clusters are generating a ton of logs and events. My team's been told we need a SIEM, and QRadar keeps coming up.

But from what I've seen with tools like Salesforce and Zendesk, enterprise platforms often struggle with modern, dynamic infrastructure. Is QRadar actually good at ingesting and correlating logs from containers, k8s control plane, and cloud APIs without constant manual tuning?

Specifically:
* Does it handle ephemeral IPs and pod labels natively?
* What's the real effort to get actionable alerts, not just raw log storage?
* Are there better options built for this from the ground up?



   
Quote