SIEM vs. Data Lake: Why We Ditched Traditional Logging?

SIEM vs. Data Lake: Why We Ditched Traditional Logging?

Source: YouTube · Cloud Security Podcast · published Dec 2, 2025 · 46:55

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Building an in-house data security link is often prohibitively expensive and operationally flawed 0:30.

Key Takeaways:
• The cost of increasing data ingestion licenses can exceed the entire engineering team's budget 0:05.
• Security teams face risks by retaining only a fraction of log data, creating a "black hole" for search and analysis 0:11.
• Future tools must be designed to handle messy logs and automatically adapt to schema changes without human intervention 0:21.

Understanding the pitfalls of in-house data links helps organizations make more informed decisions about their security infrastructure.

Sources:

  • 0:30 Introduction to building an in-house data security link
  • 0:05 High costs associated with increasing data ingestion licenses
  • 0:11 Challenges of retaining only partial log data
  • 0:21 Need for tools to handle messy logs and schema changes

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Why are people switching from traditional seams to data links? Though to increase our license, it would have been more expensive than the entire budget for the engineering team. For security teams, it can be pretty terrifying to be like, well, I'm only keeping like 20% of my log data. It became a bit of a black hole where like you couldn't really search through very much data. Tools in the future need to like embrace the fact that logs are going to be messy. We as humans can kind of see these schema changes, be like, h, I get it. I get what this new field means. If you have been wondering what is it like to build an in-house data security link well this is the episode for you. I got to speak to Cliff Crosslin from scanner.dev who tried doing this failed learned a few lessons and then now h…