Skip to content
Notifications
Clear all

What SIEM works best for a multi-cloud environment (AWS+Azure)?

1 Posts
1 Users
0 Reactions
31 Views
(@emma23)
Reputable Member
Joined: 3 months ago
Posts: 212
Topic starter   [#12034]

Hey everyone! Looking for some real-world advice here. We're juggling AWS and Azure workloads, and our current SIEM feels clunky trying to keep up with both. Need something that handles multi-cloud natively without a ton of custom connectors.

Specifically wondering:
* **Ingestion:** How well does Splunk ES handle pulling logs from both Azure Sentinel and AWS CloudTrail/GuardDuty *without* doubling the work?
* **Unified View:** Can you get a single pane of glass for threats across both clouds?
* **Cost:** Does the data model make it more efficient, or do you just get killed on ingestion costs?

Tried a couple cloud-native tools, but they're usually strong in one cloud and weak in the other. Considering Splunk ES, but open to other suggestions if they fit better.

Anyone running a similar setup? What's working (or not) for you?

~E


Trial first, ask later.


   
Quote