Fabulous for small IT teams and organizations
Use Cases and Deployment Scope
Blumira is our SIEM. We forward logs from lots of devices to Blumira via syslog and a few direct integrations. Blumira analyzes and processes those logs to look for IOCs and other risks. Blumira helps monitor activity on devices where we cannot install our antivirus agent -- effectively filling a gap in our coverage.
Pros
- The user interface (for managing, reporting) is intuitive and is easy to use
- The setup / onboarding process was very easy
- Support has been wonderful (and personal)
Cons
- We've had a few suggestions for improving some of the built-in "workflows" -- steps that we are instructed to take by Blumira for specific "findings"
- There are a few improvements about reporting I'd like to see
Return on Investment
- Now when we have a security audit or need to completed a cybersecurity insurance application, we answer "Yes" to the "Do you have a SIEM?" question.
- It has provided awareness and visibility of events and situations on our system that we were completely blind to before.
Alternatives Considered
AlienVault OSSIM, LogRhythm NextGen SIEM Platform, FortiSIEM, Graylog, LogPoint, Rapid7 InsightIDR, Sumo Logic and Securonix Next-Generation SIEM
Other Software Used
LastPass for Business, BlackBerry Protect (CylancePROTECT), BlackBerry Optics (CylanceOPTICS)
