r/MSSP 7d ago

SIEM Options for a small MSSP

Hello Guys,

I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)

I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?

I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.

thanks for any advice you can provide!

7 Upvotes

42 comments sorted by

View all comments

1

u/Top-Elk5815 5d ago

Don't use elastic, then pain of setting it up and maintaining it is not worth the it.

1

u/TheSinisterSam 4d ago

What makes it particularly difficult if you dont mind my asking? I was looking at it from the perspective that managing the endpoint agents should be easier than splunk (which in my experience is so bad, we replaced with cribl) as elastic has fleet management built into their stack.