SIEM
  • 07 Jul 2023
  • Dark
    Light

SIEM

  • Dark
    Light

Article summary

Service Overview

Expedient SIEM is a powerful platform that provides the infrastructure and interface to allow clients to quickly detect and investigate security incidents so their security team can plan an effective response. Expedient maintains the hardware platform, software updates, licensing, and ongoing maintenance as a managed service so clients can focus on the security posture of their environment and not the platform monitoring it. Clients have full access to view and create dashboards, create custom alerts, and integrate operating system and application logs and events to gain full visibility into their security posture.

Service Features

  • Pay per endpoint
  • Dedicated instance
  • Monitor security across any cloud or platform
  • Powerful out-of-the-box dashboards
  • Integrated with other Expedient services
  • Guided dashboard creation
  • Customized retention options

Default Deployment Settings

  • Dedicated instance
  • 30 days of retention
    • Longer retention is available via object storage
  • Default set of dashboards

Use Cases

  • Security monitoring and alerting
  • Event management
  • Security log analysis
  • Cloud security monitoring
  • Application security monitoring
  • Operating system security log analysis

Responsibility and Accountability Matrix

SIEM Responsibility Matrix 

Platform

Task 

Expedient 

Client 

Co-Managed  

Co-Managed tasks can be performed by Expedient or Client based on Client's preference 

Procure, Install, Configure, Manage and Maintain Hardware 

 

 

 

Procure, Install, Configure, Manage and Maintain Software 

 

 

 

Capacity Management & Reporting 

 

 

 

Management Console User and Access Management 

 

 

 X

 

Management

Install Agents - Windows 

 

 

Expedient will assist with agent installs

Configure Agents - Windows 

 

 

 

Install Agents - Linux

 

 

Expedient will assist with agent installs

Configure Agents - Linux

 

 

 

Monitoring

Deploy standard dashboards

X



Expedient creates default dashboards for Expedient services and operating system monitoring. Clients can create additional dashboards to meet more specific needs.

Create custom dashboards


X



Configure Expedient service integrations

X



Expedient will configure all integrations with Expedient services

Configure third party/external integrations


X



Monitoring and alerting for alarm thresholds


 

X

Expedient will create a set of default alarms, clients can create custom alerts and modify default alerts as necessary

Troubleshoot alerts

 

 

X

Expedient services are limited to tasks with the operating system, monitoring agent, and Expedient services. Clients are responsible for application-level troubleshooting

Supported Platforms

Applications/Platforms Supported

Expedient Services

  • Expedient Enterprise Cloud
  • Expedient Dedicated Private Cloud
  • Expedient vColo
  • Cloud Data Protection
  • Push Button DR
  • Endpoint Security
  • Micro Segmentation
  • Identity Management
  • Multi-Cloud Firewall
  • Juniper vSRX
  • Secure User VPN
Guest Operating Systems
  • Windows Server 2016 to 2022
    • Windows Server 2012 will be end of support in 2023
  • Linux: RHEL/CentOS 6.6+ | Ubuntu 18.04+
Physical Servers
  • Windows Server 2016 to 2022
    • Windows Server 2012 will be end of support in 2023
  • Linux: RHEL/CentOS 6.6+ | Ubuntu 18.04+

Hyperscale Cloud

  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform

On-Premises Workloads

  • Windows Server 2016 to 2022
    • Windows Server 2012 will be end of support in 2023
  • Linux: RHEL/CentOS 6.6+ | Ubuntu 18.04+

Unsupported Platforms

Applications/Platforms Not Supported

Operating Systems

  • Windows
    • Pre-Server 2012
    • Desktop versions of Windows
  • Linux
    • SUSE
    • CentOS Stream

Was this article helpful?