I think the main difference is that SOAR ingests numerous types of logs and event data infrastructure components, while SIEM can fetch data from endpoint security software and external threat intelligence feeds.
That makes sense to me. SOAR is about the collection and analysis, while SIEM is about the automation and response. We need both in a comprehensive security strategy.
Haha, yeah, that one was a bit of a head-scratcher. I can just picture a SOAR system being like, 'Nah, I'm not going to alert you to that suspicious activity. I'll just handle it myself!'
Haha, yeah, that one was a bit of a head-scratcher. I can just picture a SOAR system being like, 'Nah, I'm not going to alert you to that suspicious activity. I'll just handle it myself!'
A) SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds
C) SIEM raises alerts in the event of detecting any suspicious activity, and SOAR automates investigation path workflows and reduces time spent on alerts
A) SOAR ingests numerous types of logs and event data infrastructure components and SIEM can fetch data from endpoint security software and external threat intelligence feeds
upvoted 0 times
...
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
My
12 months agoMacy
12 months agoRoslyn
12 months agoMy
1 years agoMacy
1 years agoCecil
1 years agoDelpha
1 years agoIzetta
1 years agoOren
1 years agoCarissa
1 years agoLezlie
1 years agoRodrigo
1 years agoArletta
1 years agoLawrence
1 years agoChan
1 years agoMariko
1 years agoFelix
1 years agoGracia
1 years ago