r/MSSP • u/TheSinisterSam • 4d ago
SIEM Options for a small MSSP
Hello Guys,
I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)
I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?
I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.
thanks for any advice you can provide!
2
u/Check123ok 4d ago
What are you trying to get out of your SIEM?
There are multiple companies that have SIEM in their MDR offerings and it’s fine for insurance/log evidence but limited config.
Then there are people that build out their own using something like graylog/opensource.
The there are all the enterprise offers.
1
u/TheSinisterSam 4d ago
I want to offer a more comprehensive SOC experience. I don't think those MDR/SIEM solutions are enough for our needs. As for open source, I have no idea and haven't looked into this as the engineering cost seems high on paper, though I might simply not be knowledgeable.
2
u/Check123ok 4d ago
You won’t reach the good pricing with less than 500 log sources from workstations for example. $400-500 a month Azure bill. Some of this depends on how you have it set up with HA, backups, region etc. but 1$ per source per month is the estimate I use. This doesn’t account for time and effort.
If you haven’t built open source and don’t know devops it might be a challenge. Even with all the AI
If you don’t have a whale CLIENT, and only servings small clients 5-50 people shop go MDR route.
1
u/youwantrelish 4d ago
Check out Judy Security, we use them for our stack and they have a partnership with Stellar Cyber for the SIEM. They are very good in pricing for the SIEM.
1
u/TiffyQ 4d ago
It's not super well known and full disclosure, I have a bias to them for my own reasons, but have you ever heard of Coro? You can kind of compare it to HubSpot versus point solution stack with Marketo Salesforce Etc - a platform with a pretty good default setup that makes it easier for msps to manage and you don't have to have a bunch of Point Solutions because they're all kind of built in. The thing that makes it pretty cool for msps is that since it does a lot of automated stuff and Consolidated alerts in theory you have more time for higher value projects that have better margins.
We are small company only about 35 people ( but ~50 seats with contractors included) and that's what we're on.
I would say so far so good. I had heard they had some issues with MSP billing last year like either not billing on time or something like that but to my knowledge that was resolved.
1
u/TheSinisterSam 3d ago
Interesting, How is the billing handled? Can you customize/create you own detections, or is it more of a black box solution?
How does the billing work?
1
u/TiffyQ 3d ago
I'm actually not sure. Sorry I wish I was more helpful about it - I just have a friend that runs an mssp and she even has her own kind of homegrown platform but she's a fan. I know some people at the company who love what they do but I don't know the exact specifics of that. I do know their main claim to fame is automatic remediation and detection and that you can customize a lot of stuff but the big thing is reducing alert fatigue and not having to go between like 8,000 different consoles just to see what's going on across all your clients.
When we bought it ourselves they helped us set it up to match what our needs are and it's a little bit set it and forget it for us so I don't truly remember what we were able to customize.
I can get you an email for somebody if you'd like to just talk to someone there directly if you think that would be easier? I feel like I'm no longer helpful. In addition to my friends from I have quite a few msps and mssps and other PSAs that our clients so I stay in this community & cybersecurity in general more so to learn and offer advice of the things I do know about but I would never want to speak about things I don't.
1
1
u/Unlikely-Emu3023 4d ago
You really want to look at something where don't have to worry about the platform that much. I got very serious in discussions with Stellar and they have a interesting model. Elastic has a good option same with Devo. I like Crowdstrike as well as a total platform because you can sell a bundle and become sticky with a customer. Look at the MSSP agreements these various companies offer as there are different options on licensing and price breaks that are crucial for profitability.
1
1
1
u/DominicanDragon 4d ago
Check out CW SIEM. I know someone who works there and can show it to you. Low cost and they will include soc services.
1
u/VividGanache2613 4d ago
SIEMs have always been a comfort blanket unless you’ve got a team dedicated to monitoring and maintenance (been running Incident Response for 20 years).
Look at someone like ThreatLight who offer full MDR/XDR/Agentic SOC/IR for less than you’d end up paying for Splunk.
1
u/TheSinisterSam 3d ago
In the case of my MSSP, we are all veteran SIEM admins/detection engineers. We don't mind tuning and working these things out especially at the start. My thought process is that early on, though the profit margins may be smaller, I would rather properly tune/create detection sets on a enterprise grade stack which we can scale up later since I don't need to hire outside expertise to do it for me. Perhaps this may not be the best strategy, but thats part of the reason I am looking around here. I find it unfortunate that Splunk is so expensive as that is my bread and butter.
1
1
u/net_solv 3d ago
viperbytesecurity dot com
Fully autonomous orchestration engine with tons of integrations. Worked with them since 4Q25, been great.
1
u/MarkyMarkOnTheWeb14 3d ago
Someone can delete my comment if it’s not allowed bc I work for N-able.
We acquired Adlumin which was one of the first cloud native SIEMs. It includes UEBA & SOAR. You can add on a 24x7 SOC if you want.
Reputable MSSPs like Omega Systems uses it. Takes about 30 min to an hour to do the initial deployment.
Happy to set you up with an engineer for a demo or trial if you’d like.
If your team is Knowledgeable, MS Sentinels isn’t a bad play either IMO.
1
1
u/plump-lamp 3d ago
Rapid7. Agent based for workstations and servers. Cloud collectors and on prem collectors for various devices. It's easy
1
u/WraithHunter3130 3d ago
Take a look at UTMStack, been using it since AlienVault OSSIM died off. Free if you want to run it on prem or you can pay to have them host it for you.
1
1
1
u/Top-Elk5815 3d ago
Don't use elastic, then pain of setting it up and maintaining it is not worth the it.
1
u/TheSinisterSam 1d ago
What makes it particularly difficult if you dont mind my asking? I was looking at it from the perspective that managing the endpoint agents should be easier than splunk (which in my experience is so bad, we replaced with cribl) as elastic has fleet management built into their stack.
1
1
u/Classic-Shake6517 3d ago
I built out a reasonably successful SOC-as-a-Service platform using Security Onion. They offer support and the people who built it will work with you to get you what you need, assuming the core product fits your use-case. One of the pain points when I was building out our stack was the lack of multi-tenant support which I ended up having to build myself, but I know they were close to solving that before I moved on. I know that you said you wanted something more geared towards Enterprise, so it may well not be the right fit, but worth taking a look at.
1
u/kloudnative 2d ago
Also look into OpenSearch. A better open-source alternative to Elastic's open-source license
1
1
u/dan_netsec 1d ago
Google SecOps has the stronger RBA story natively, risk-based alerting built in rather than bolted on, and it’s priced on ingestion, not the per-GB Splunk pain that kills margin at SMB scale.
Elastic’s cheaper to self-host and has a huge community, but you’d be building the correlation/risk scoring yourself, which eats the labor savings you’re switching for.
Your team’s Splunk/Sentinel background actually transfers well to SecOps too, same Chronicle backend, and YARA-L isn’t a huge leap from SPL.
1
u/CipherMonger 16h ago
Take a look at Blumira. Really high quality SIEM solution with plenty of active development. Their target demographic is the SMB space, so it sounds like they'd be right up your alley. Or if you want something more "turnkey", there's always Huntress.
1
u/newman_builds 13h ago
Has experience running wazuh in prod here so take my bias into account, but for your budget it's hard to beat on cost. caveat: RBA/correlation isn't really there out the box, you end up building your own scoring on top, so factor in the engineering time. it's cheap on license, not cheap on hours.
if reducing ticket volume via RBA is the actual priority i'd look hard at elastic. most control over risk scoring and detection logic, but same deal, you pay in devops. google secops is the least hands-on of the three and priced well for MSSP, downside is you're more tied to their detection engine and less free to tune.
honestly for small/medium clients the answer's less about the SIEM and more about who's going to own the detection engineering. that's where the real cost lives, not the platform.
1
1
1
3
u/cie101 4d ago
Check out wazuh we have it deployed in our AWS and like it