Better Together: Leveraging Your Observability Tools as a SIEM
Identifying root causes and coordinating across teams during a security incident is a daunting task, often complicated by the use of disparate tools across departments. In high-stress situations, the need for seamless communication and efficient problem-solving is paramount, yet these challenges are amplified when teams rely on different systems. In this talk, we’ll explore how integrating your existing observability tools into a cohesive Security Information and Event Management (SIEM) solution can streamline incident response and enhance overall security posture. We’ll discuss the benefits of unifying these tools, enabling more effective collaboration, faster root cause identification, and improved security outcomes. Additionally, we’ll address the challenges that come with integrating these systems, from technical hurdles to organizational resistance, and offer practical strategies for overcoming them. By the end of this session, you’ll understand why combining observability and security tools can lead to a more resilient and responsive infrastructure, ultimately making your organization better equipped to handle security incidents.
Speaker
-
Jesús EspinoVictoriaMetricsJesús Espino is an Open-Source and software development enthusiast, and he has been one of the starters or contributors in some interesting Open-Source projects like Taiga, Penpot, Mattermost, Focalboard, or testcontainers-go. He is a big fan of learning new things, especially programming languages and he loves to dive deep into technical details. He also writes a blog named internals-for-interns.com where he talks about the internals of open source projects in an approachable way. Currently, he is working in Go and Typescript as a Principal Engineer at VictoriaMetrics.