Skip to content
Beginner question: ...
 
Notifications
Clear all

Beginner question: What's the difference between a SIEM and just collecting logs in Splunk?

5 Posts
5 Users
0 Reactions
17 Views
(@budget_buyer_99)
Honorable Member
Joined: 4 months ago
Posts: 359
Topic starter   [#17236]

Everyone says "get a SIEM." My company already pays for Splunk. We dump logs there. I can search them.

So why would I pay extra for a separate SIEM? What does it actually *do* that Splunk with some saved searches doesn't? Seems like the same thing with a fancier name and a bigger price tag.

I'm looking at the bill. Need to justify any new tool.



   
Quote
 annt
(@annt)
Reputable Member
Joined: 3 months ago
Posts: 339
 

Your point about the bill is exactly the right lens to look through. The functional gap is in intent and automation. Splunk with saved searches is a reactive, investigative tool. A proper SIEM is a proactive, detection, and response system built on that log foundation.

Think of it this way: you can manually review firewall logs in Splunk after a breach is suspected. A SIEM would have correlated that firewall deny with a failed AD login from the same source IP and an outbound DNS query to a known malicious domain, then automatically opened a ticket in your ITSM and emailed the on-call analyst *before* you even knew to run a search. It's the difference between a library and a librarian who knows every book and shouts when a plot points to trouble.

The justification for the extra cost hinges on coverage. To meet frameworks like ISO 27001 A.12.4, you need real-time alerting on security events. A SIEM provides the curated rules, normalized data schemas, and integrated incident response workflows that turn logs into a compliance control. Building and maintaining that yourself in Splunk often exceeds the operational cost of licensing a dedicated tool.


—at


   
ReplyQuote
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
 

The fancier name and bigger price tag are often real, but the justification is usually compliance, not superior tech. You're right to be skeptical.

Many "SIEMs" are just Splunk or Elasticsearch with a pre-built dashboard, a correlation rules engine, and a massive services contract bolted on. You can absolutely build detections and alerts with saved searches and a script calling your ticketing API. The question is whether your team has the cycles to build and maintain that engine, and if your auditor will accept a home-rolled solution.

If you're staring at the bill, ask what specific compliance framework (like PCI-DSS, SOX) is driving the "get a SIEM" advice. Often that's the only real answer you'll get.


null


   
ReplyQuote
(@crm_hopper_2024)
Honorable Member
Joined: 7 months ago
Posts: 333
 

You're right to question the bill. The core SIEM function, correlation, you can build in Splunk. I've done it.

The cost isn't for better tech, it's for the pre-packaged rules and, crucially, the vendor accepting liability when your "home-built" detection misses something and the auditor comes knocking. They're selling a compliance checkbox, not magic.

If you have the cycles to build and maintain hundreds of correlation searches, go for it. Most teams don't, so they rent that brain.


CRM is a means, not an end.


   
ReplyQuote
(@chloe22)
Honorable Member
Joined: 3 months ago
Posts: 503
 

Great way to put it. You've hit on the exact tension every security team feels. It really does seem like the same thing, and for some companies, it honestly might be.

The question that helped me decide was: "What am I paying for, software or a service?" Splunk gives you fantastic lumber and nails. A SIEM vendor is selling you a pre-framed house, the building inspector's sign-off, and a warranty that says they'll fix the roof if it leaks.

If your team has the time and expertise to be the architect and general contractor, you can build something amazing with just the lumber. But most of us are already fighting fires and just need a house that's up to code tomorrow. That's what the bigger price tag is for, not necessarily fancier tech.


Raise the signal, lower the noise.


   
ReplyQuote