cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
176
Views
0
Helpful
1
Replies

Does XDR replace SIEM and SOAR?

Meddane
VIP
VIP

Extended Detection and Response (XDR) - Versus - Security information and event management (SIEM).

After the acquisition of Splunk as a SIEM and the launch of Cisco XDR, which one is better for detection and response?

Capture d'écran 2024-04-24 110443.png

 

1 Reply 1

XDR isn't a SEIM... you aren't going to send all of the Windows logs, switch logs, etc. to XDR.

And you can't do your own raw searches into the data, nor can you write your own correlation rules across all of it.

The Automation engine could replace a SOAR, especially of you have mostly Cisco security tools, or the ones they're supporting direct integrations with.