Because legacy SIEMs create a very high signal-to-noise ratio, they've become relegated to satisfying compliance requirements and not much else.
Here are the features needed in a Next-Gen SIEM solution-combining the latest technology with a comprehensive knowledge of how threats emerge:
Collect and manage data from all available sources
Present-day threats typically span multiple data sources. To be effective, every data source must be available to your next-gen SIEM for it to analyze and correlate the data. (See Figure 1.) This includes cloud service data, on-premise log data (security controls, databases, and application logs), and network data (flows, packets, etc.).
Your SIEM should also include centralized, remote data management. After you have all connectors configured and running, this enables you to easily manage them (start, stop, update, reconfigure) from any location.