
SIEM vs. Data Lake: Why We Ditched Traditional Logging?
Source: YouTube · Cloud Security Podcast · published Dec 2, 2025 · 46:55
Building an in-house data security link is often prohibitively expensive and operationally flawed 0:30.
Key Takeaways:
• The cost of increasing data ingestion licenses can exceed the entire engineering team's budget 0:05.
• Security teams face risks by retaining only a fraction of log data, creating a "black hole" for search and analysis 0:11.
• Future tools must be designed to handle messy logs and automatically adapt to schema changes without human intervention 0:21.
Understanding the pitfalls of in-house data links helps organizations make more informed decisions about their security infrastructure.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Why are people switching from traditional seams to data links? Though to increase our license, it would have been more expensive than the entire budget for the engineering team. For security teams, it can be pretty terrifying to be like, well, I'm only keeping like 20% of my log data. It became a bit of a black hole where like you couldn't really search through very much data. Tools in the future need to like embrace the fact that logs are going to be messy. We as humans can kind of see these schema changes, be like, h, I get it. I get what this new field means. If you have been wondering what is it like to build an in-house data security link well this is the episode for you. I got to speak to Cliff Crosslin from scanner.dev who tried doing this failed learned a few lessons and then now h…