Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more defend against cybersecurity threats in near real-time. It's goal is to ease the burden of alert fatigue, complexity of log management and lack of IT visibility.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Director in Information Technology (51-200 employees employees)
Use Cases and Deployment Scope
Blumira is our SIEM. We forward logs from lots of devices to Blumira via syslog and a few direct integrations. Blumira analyzes and processes those logs to look for IOCs and other risks. Blumira helps monitor activity on devices where we cannot install our antivirus agent -- effectively filling a gap in our coverage.
Pros
The user interface (for managing, reporting) is intuitive and is easy to use
The setup / onboarding process was very easy
Support has been wonderful (and personal)
Cons
We've had a few suggestions for improving some of the built-in "workflows" -- steps that we are instructed to take by Blumira for specific "findings"
There are a few improvements about reporting I'd like to see
Return on Investment
Now when we have a security audit or need to completed a cybersecurity insurance application, we answer "Yes" to the "Do you have a SIEM?" question.
It has provided awareness and visibility of events and situations on our system that we were completely blind to before.