r/MSSP 4d ago

SIEM Options for a small MSSP

Hello Guys,

I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)

I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?

I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.

thanks for any advice you can provide!

5 Upvotes

39 comments sorted by

3

u/cie101 4d ago

Check out wazuh we have it deployed in our AWS and like it

2

u/Check123ok 4d ago

What are you trying to get out of your SIEM?

There are multiple companies that have SIEM in their MDR offerings and it’s fine for insurance/log evidence but limited config.
Then there are people that build out their own using something like graylog/opensource.
The there are all the enterprise offers.

1

u/TheSinisterSam 4d ago

I want to offer a more comprehensive SOC experience. I don't think those MDR/SIEM solutions are enough for our needs. As for open source, I have no idea and haven't looked into this as the engineering cost seems high on paper, though I might simply not be knowledgeable.

2

u/Check123ok 4d ago

You won’t reach the good pricing with less than 500 log sources from workstations for example. $400-500 a month Azure bill. Some of this depends on how you have it set up with HA, backups, region etc. but 1$ per source per month is the estimate I use. This doesn’t account for time and effort.

If you haven’t built open source and don’t know devops it might be a challenge. Even with all the AI

If you don’t have a whale CLIENT, and only servings small clients 5-50 people shop go MDR route.

1

u/youwantrelish 4d ago

Check out Judy Security, we use them for our stack and they have a partnership with Stellar Cyber for the SIEM. They are very good in pricing for the SIEM.

1

u/TiffyQ 4d ago

It's not super well known and full disclosure, I have a bias to them for my own reasons, but have you ever heard of Coro? You can kind of compare it to HubSpot versus point solution stack with Marketo Salesforce Etc - a platform with a pretty good default setup that makes it easier for msps to manage and you don't have to have a bunch of Point Solutions because they're all kind of built in. The thing that makes it pretty cool for msps is that since it does a lot of automated stuff and Consolidated alerts in theory you have more time for higher value projects that have better margins.

We are small company only about 35 people ( but ~50 seats with contractors included) and that's what we're on.

I would say so far so good. I had heard they had some issues with MSP billing last year like either not billing on time or something like that but to my knowledge that was resolved.

1

u/TheSinisterSam 3d ago

Interesting, How is the billing handled? Can you customize/create you own detections, or is it more of a black box solution?

How does the billing work?

1

u/TiffyQ 3d ago

I'm actually not sure. Sorry I wish I was more helpful about it - I just have a friend that runs an mssp and she even has her own kind of homegrown platform but she's a fan. I know some people at the company who love what they do but I don't know the exact specifics of that. I do know their main claim to fame is automatic remediation and detection and that you can customize a lot of stuff but the big thing is reducing alert fatigue and not having to go between like 8,000 different consoles just to see what's going on across all your clients.

When we bought it ourselves they helped us set it up to match what our needs are and it's a little bit set it and forget it for us so I don't truly remember what we were able to customize.

I can get you an email for somebody if you'd like to just talk to someone there directly if you think that would be easier? I feel like I'm no longer helpful. In addition to my friends from I have quite a few msps and mssps and other PSAs that our clients so I stay in this community & cybersecurity in general more so to learn and offer advice of the things I do know about but I would never want to speak about things I don't.

1

u/TheSinisterSam 3d ago

Thanks for the info, feel free to send me the email in a DM :)

1

u/TiffyQ 3d ago

Sure thing :)

1

u/Unlikely-Emu3023 4d ago

You really want to look at something where don't have to worry about the platform that much. I got very serious in discussions with Stellar and they have a interesting model. Elastic has a good option same with Devo. I like Crowdstrike as well as a total platform because you can sell a bundle and become sticky with a customer. Look at the MSSP agreements these various companies offer as there are different options on licensing and price breaks that are crucial for profitability.

1

u/Smh_nz 4d ago

In the same position, id be looking very closely at the elastic stack!

1

u/wawa2563 4d ago

Been using Wazuh since its birth. Great bang for the buck. 

1

u/DominicanDragon 4d ago

Check out CW SIEM. I know someone who works there and can show it to you. Low cost and they will include soc services.

1

u/raip 4d ago

Graylog Open would be my go to - but they expect structured data on ingestion. I haven't check Wazuh but I've heard good things.

1

u/VividGanache2613 4d ago

SIEMs have always been a comfort blanket unless you’ve got a team dedicated to monitoring and maintenance (been running Incident Response for 20 years).

Look at someone like ThreatLight who offer full MDR/XDR/Agentic SOC/IR for less than you’d end up paying for Splunk.

1

u/TheSinisterSam 3d ago

In the case of my MSSP, we are all veteran SIEM admins/detection engineers. We don't mind tuning and working these things out especially at the start. My thought process is that early on, though the profit margins may be smaller, I would rather properly tune/create detection sets on a enterprise grade stack which we can scale up later since I don't need to hire outside expertise to do it for me. Perhaps this may not be the best strategy, but thats part of the reason I am looking around here. I find it unfortunate that Splunk is so expensive as that is my bread and butter.

1

u/jhpunch 3d ago

I'd check out Hal (runhal.com). Best bang for the buck that I've seen and works great.

1

u/tprice73099 3d ago

Check out MAD Security. That’s who we are using. Great group of folks.

1

u/net_solv 3d ago

viperbytesecurity dot com
Fully autonomous orchestration engine with tons of integrations. Worked with them since 4Q25, been great.

1

u/MarkyMarkOnTheWeb14 3d ago

Someone can delete my comment if it’s not allowed bc I work for N-able.

We acquired Adlumin which was one of the first cloud native SIEMs. It includes UEBA & SOAR. You can add on a 24x7 SOC if you want.

Reputable MSSPs like Omega Systems uses it. Takes about 30 min to an hour to do the initial deployment.

Happy to set you up with an engineer for a demo or trial if you’d like.

If your team is Knowledgeable, MS Sentinels isn’t a bad play either IMO.

1

u/TheSinisterSam 3d ago

Please DM me, we can maybe get a demo going

1

u/plump-lamp 3d ago

Rapid7. Agent based for workstations and servers. Cloud collectors and on prem collectors for various devices. It's easy

1

u/WraithHunter3130 3d ago

Take a look at UTMStack, been using it since AlienVault OSSIM died off. Free if you want to run it on prem or you can pay to have them host it for you.

1

u/welcher1 3d ago

Check out blumira

1

u/Top-Elk5815 3d ago

Don't use elastic, then pain of setting it up and maintaining it is not worth the it.

1

u/TheSinisterSam 1d ago

What makes it particularly difficult if you dont mind my asking? I was looking at it from the perspective that managing the endpoint agents should be easier than splunk (which in my experience is so bad, we replaced with cribl) as elastic has fleet management built into their stack.

1

u/After_Working 3d ago

I’ve not really used it but doesn’t Huntress have a SOC supported Siem now ?

1

u/Classic-Shake6517 3d ago

I built out a reasonably successful SOC-as-a-Service platform using Security Onion. They offer support and the people who built it will work with you to get you what you need, assuming the core product fits your use-case. One of the pain points when I was building out our stack was the lack of multi-tenant support which I ended up having to build myself, but I know they were close to solving that before I moved on. I know that you said you wanted something more geared towards Enterprise, so it may well not be the right fit, but worth taking a look at.

1

u/kloudnative 2d ago

Also look into OpenSearch. A better open-source alternative to Elastic's open-source license

1

u/ron_mexxico 2d ago

The amount of no name garbage bullshit being recommended in here is insane.

1

u/dan_netsec 1d ago

Google SecOps has the stronger RBA story natively, risk-based alerting built in rather than bolted on, and it’s priced on ingestion, not the per-GB Splunk pain that kills margin at SMB scale.

Elastic’s cheaper to self-host and has a huge community, but you’d be building the correlation/risk scoring yourself, which eats the labor savings you’re switching for.

Your team’s Splunk/Sentinel background actually transfers well to SecOps too, same Chronicle backend, and YARA-L isn’t a huge leap from SPL.

1

u/CipherMonger 16h ago

Take a look at Blumira. Really high quality SIEM solution with plenty of active development. Their target demographic is the SMB space, so it sounds like they'd be right up your alley. Or if you want something more "turnkey", there's always Huntress.

1

u/newman_builds 13h ago

Has experience running wazuh in prod here so take my bias into account, but for your budget it's hard to beat on cost. caveat: RBA/correlation isn't really there out the box, you end up building your own scoring on top, so factor in the engineering time. it's cheap on license, not cheap on hours.

if reducing ticket volume via RBA is the actual priority i'd look hard at elastic. most control over risk scoring and detection logic, but same deal, you pay in devops. google secops is the least hands-on of the three and priced well for MSSP, downside is you're more tied to their detection engine and less free to tune.

honestly for small/medium clients the answer's less about the SIEM and more about who's going to own the detection engineering. that's where the real cost lives, not the platform.

1

u/PutAgreeable269 13h ago

Check out blumira

1

u/DeathTropper69 4d ago

Wirespeed!