Automate threat detection and response with Blumira's cloud SIEM. Get end-to-end detection & response in one easy-to-use platform.
Nutzerbewertungen filtern (8)
Fantastic SIEM for my customers
Kommentare: your sales reps are fantastic and responsive
much cheaper than say Splunk plus easier to set up
not alot of folks have heard of your company
In Betracht gezogene Alternativen:
Blumira solves the problem of SOC
Kommentare: Extremely positive; they are engaged with their customers and are transparent with their development efforts which help make us successful. Their rapid and knowledgeable communication has blown me away.
The platform has done an amazing job of taking the various events, alerts, alarms, and other notifications and boiling them down into actionable alerts that any member of an IT team can work with and react against. Alert fatigue is a real concern, and the fact that our support staff can be given the infrequent and important findings -- while being given a playbook on how to respond -- is the reason this software is successful.
While the initial setup was straightforward, it did not include the same large amount of documentation that other vendors provide. This did involve then reaching out to Blumira support, which has been, hands-down, the most knowledgeable and fastest support team that I have ever used in my 20 years of utilizing untold numbers of networking and security vendors.
Antwort von Blumira
Thanks for the positive response! We greatly appreciate having you as a customer. Your feedback is also welcomed. We also felt we didn't have accessible documentation and have published our documentation publicly on Blumira's website for all at https://www.blumira.com/integrations/
Kommentare: Blumira implementation was easy, with log collector setup done by script, templates for event forwarding from log sources. Use of this product has greatly reduced the time required of our limited staff searching logs for suspicious activity or indications of misconfiguration. Alert Event information and explanations enable rapid investigation and resolution of most incidents.
Automatic event alerts for suspicious activities allows us to begin investigation soon after a suspicious event. Automated report generation for less sensitive activities allows us to monitor actions of interest to our organization. The Report Builder UI is straightforward and with practice can be used to create detailed reports of log activity for specific events, as is needed during investigations. Event management UI provides for communication to Blumira staff for additional support, attachment of documents from investigations and documenting the resolution of the event.
It takes some practice and experimentation to identify which fields to use in filtering logs into reports. Blumira normalizes the logs for storage in the database and it can be challenging to get the right data items into the report you want. However, Blumira support is always ready to help figure it out.
Blumira is an AWESOME hosted SIEM/MDR solution
Kommentare: Overall, Blumira is an AWESOME hosted SIEM/MDR solution at an extremely reasonable price point. It's no Splunk, but it's also a fraction of the cost, and top-notch support is included in the price. It should be able solve most organizations' problems for log collection and compliance, and their out-of-the-box detections catch most bad things without false-positives or needing to be tuned. If they continue adding the features they say they're adding, Blumira's definitely a solution to keep your eye on.
Blumira doesn't need agents, and it's really easy to setup and use. The built-in detections will quickly start to call-out risky behavior or settings that could be dangerous. So far, we haven't seen any missed detections or false-positives.
Requirement for a VM to collect logs - even if your integrations are all cloud (e.g. AWS, M365, etc), you still need to deploy a VM on your network to connect your cloud apps to Blumira's cloud. I was told this may change in the future. Detections aren't user-configurable, but Blumira's support is extremely helpful and will change configurations for you if required. I was told this may change soon. Views/dashboards aren't configurable, and reports aren't 'very sexy' (i.e. they give you the data you want in a CSV - no fancy PDF with graphs, logos, etc.)
A great solution that works as promised.
Kommentare: We have had a couple of instances where users clicked on a malicious link and their machine started password spraying. Alerted and the device was isolated and remediated in less than a half hour. I am afraid to think how long it would have been that we had this malicious software in our environment without Blumira.
The ease of implementation was incredible. Other solutions were going to be months to a year to fully deploy.
Not really any cons about the solution. They are a newer company and are great to work with when we need to new features added.
All detection and response should be this easy
Kommentare: Increased visibility and managing my security operations efforts.
Easy deployment, easy integration. High fidelity findings and alerts. Context in consideration backed by threat intelligence. Plain actionable language in alerts. If you are a Cisco shop and you are struggling with Secure-X, just stop and call Blumira today.
Reporting and search could be more user friendly.
Review of Blumira
The Blumira team has been super responsive to any of my requests and willing to jump on a call if needed. The platform is straight forward and easy to use.
Nothing so far, everything has been working just fine...
Antwort von Blumira
vor 12 Monaten
We appreciate your great review, Jason!
Peace of mind!
Kommentare: Overall, very happy. Our [SENSITIVE CONTENT HIDDEN] was super helpful in making sure we totally understood the ins and outs of the product. They were able to help us connect all of our 3rd party integrations, get our Windows and Linux logs ingested into Blumira, explained how to make best use of the software for our particular organization, and tons more.
With the Technical Account Management team guiding you along every step of the way, getting everything up and running was a breeze!
Currently, no bulk action abilities. I was told this will be coming soon though so, not really a big deal for us.