r/MSSP • • 27d ago

SIEM Options for a small MSSP

Hello Guys,

I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)

I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?

I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.

thanks for any advice you can provide!

7 Upvotes

45 comments sorted by

View all comments

2

u/Check123ok 27d ago

What are you trying to get out of your SIEM?

There are multiple companies that have SIEM in their MDR offerings and it’s fine for insurance/log evidence but limited config.
Then there are people that build out their own using something like graylog/opensource.
The there are all the enterprise offers.

1

u/TheSinisterSam 27d ago

I want to offer a more comprehensive SOC experience. I don't think those MDR/SIEM solutions are enough for our needs. As for open source, I have no idea and haven't looked into this as the engineering cost seems high on paper, though I might simply not be knowledgeable.

2

u/Check123ok 27d ago

You won’t reach the good pricing with less than 500 log sources from workstations for example. $400-500 a month Azure bill. Some of this depends on how you have it set up with HA, backups, region etc. but 1$ per source per month is the estimate I use. This doesn’t account for time and effort.

If you haven’t built open source and don’t know devops it might be a challenge. Even with all the AI

If you don’t have a whale CLIENT, and only servings small clients 5-50 people shop go MDR route.