Ecosystem of Insights: Building Operation Dashboards That Enable Teams
SANS Blue Team Summit 2023
Ecosystem of Insights: Building Operation Dashboards That Enable Teams
Speaker: Ryan Thompson, Senior Researcher, Crowdstrike
So you've bought a next generation SIEM and have done the heavy lifting of ingesting and parsing disparate data from a dozen sources. What happens next? In order to make use of this new platform it requires that analysts become experts in the search syntax, log format and parsing structure across multiple log types. Scaling this skillset out across an entire SOC is difficult if not impossible. Building operational dashboards lowers the barrier for a SOC to get answers from a dataset. It's simply not enough to just throw a handful of widgets onto a "single pane of glass" and call it a day. Building functional dashboards relies on combining the disciplines of data analysis and user experience. When built right, dashboards can do more than simply visualize data, they can enable an entire team/organization to quickly ask questions of data without needing to be an expert with the platform.
View upcoming Summits: http://www.sans.org/u/DuS