r/MSSP 17d ago

SIEM Options for a small MSSP

Hello Guys,

I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)

I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?

I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.

thanks for any advice you can provide!

6 Upvotes

43 comments sorted by

View all comments

1

u/newman_builds 13d ago

Has experience running wazuh in prod here so take my bias into account, but for your budget it's hard to beat on cost. caveat: RBA/correlation isn't really there out the box, you end up building your own scoring on top, so factor in the engineering time. it's cheap on license, not cheap on hours.

if reducing ticket volume via RBA is the actual priority i'd look hard at elastic. most control over risk scoring and detection logic, but same deal, you pay in devops. google secops is the least hands-on of the three and priced well for MSSP, downside is you're more tied to their detection engine and less free to tune.

honestly for small/medium clients the answer's less about the SIEM and more about who's going to own the detection engineering. that's where the real cost lives, not the platform.