❌

Normal view

The Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026

14 August 2026 at 01:09

Lately, I’ve been reading a lot of insightful posts related to best practices in SIEM, detection, and logs (written in 2026). The interesting bit is that a lot of these best practices looked good to me and made senseβ€Šβ€”β€Šand yet, they felt incredibly familiar…

As I dug deeper, I realized they reminded me of things I had written 10, or sometimes even 20 (23 in one case) yearsΒ ago.

Dark and ancient art of SIM/SEM to becomeΒ SIEM

What does this mean? I hope you don’t take this post as something written purely to prove that I’m very smart and totally prescient (I am smart / I am not prescient). No, the actual lesson here is that things changed much less at many organizations than peopleΒ assume.

So, let’s review some of the older wisdom from the mid-2000s and early 2010s and match it up against what people report as today’s best practices.

#1 Centralization

Let’s start with pure comedy. In 2003, I recommended that people … wait for it… centralize security data (funny enough, in 2023, I briefly questioned this idea). But on a more serious note, this is stillβ€Šβ€”β€Šmostlyβ€Šβ€”β€Šgood advice, with some notable exceptions [A.C.β€Šβ€”β€Šlook at that emdash sucker there, gotΒ it?].

Excerpt from Anton Chuvakin 2003Β slide

#2 Context

I am surprised about it myself, but back in 2003 I was a big fan of adding what later became known as context data into a SIEM. Asset info, vulnerability scans, etc need to go into your SIEM (well, SIM and SEM at the time; SIEM was born inΒ 2005).

Excerpt from Anton Chuvakin 2003Β slide

#3 Planning

Since the day I first laid my eyes on a SIEM in January 2002 (well, technically, it was a SIM), I realized that project planning makes or breaks a SIEM deployment. 20+ years did NOT teach many this lesson, as modern advice, sadly, is the same. Generic advice? Sure, but also evergreen!

Excerpt from Anton Chuvakin 2011Β slide

#4 Buy vsΒ DIY

You may think because I worked for vendors, I was always a fan of β€œbuy from a vendor” as a default choice, and only resort to β€œbuild” or β€œbuy then build” as an exception.No, I saw too many DIY SIEM disasters. Here we confirm that despite major changes in tooling (AI agents), for most organizations build vs buy decision remained largely the same, forΒ now.

Excerpt from Anton Chuvakin 2010Β slide

(a fun ancient exception: a certain β€œI-suspect-who” had to analyze 300TB (~ 1 trillion messages) of logs in 2005, and advice they were given is: DIY, nothing commercial can handle it … and as we learned later won’t for another 5–7 years atΒ least)

#5 Output-driven SIEM

The idea of β€œOutput-driven SIEM” was stolen by me in 2011 and then popularized widely my Gartner β€œmegaphone.” I did a refresh on this in 2025, but, in brief, it means β€œdeploying your SIEM in such a way that NOTHING comes into your SIEM unless and until you know how it would be utilized and/or presented.” This is very relevant today, because in the past it was hardware and not perhaps it means tokens. But β€œSIEM costs kill” messageΒ remains.

#6 CrownΒ Jewels

Sometime around 2013, I was giving many clients this advice: do NOT start your security monitoring (really, D&R) scope from the most important assets, or crown jewels. Many a CISO argued hard (β€˜but Anton, what about β€œimportant first.”’ Yes, SAP is important but if you onboard SAP logs before firewall logs, you will probably die in the process. And step 2 will never happen. Modern advice seems to match perfectly.

#7 Retention

β€œKeep logs. If you don’t know better, keep logs for a year.” I said around 2006–2008. Then in 2019, I got somewhat shocked that keeping logs for a year is seen as a luxury by many. Today with data lakes and all sorts of crazy cloud storage people … well… often still don’t keep logs longΒ enough.

Excerpt from Anton Chuvakin 2011Β slide

#8 SIEM vs Log Management

SIEM vs LM was a hot topic in the mid-2000s. We had architectured for broad collection in LM and security focused subset in a SIEM. Today this just means SIEM and a data lake. So, this also aged veryΒ well.

#9 Log Data Mining akaΒ UEBA

A lot of my early work in what I called ”log data mining” predated UEBA, and my predictions that rules will be complemented by analytics (hi Captain Obvious!) aged weirdly. They agend well, then not well, then well again. Today we have non-deterministic AI analyzing logs, and back then we had Marcus Ranum β€œNBS” for Never BeforeΒ Seen….

#10 Misc

In my consulting days (pre-Gartner, which means pre-2011), I did a lot of β€œbest / worst practices” presentations, such as this one. I think these aged well, but perhaps because they were a bit generic. Example that aged very wellΒ include:

  • β€œPhased Approach: Rather than feeding β€œall” logs into a SIEM immediately, organizations should start with limited devices (e.g., DMZ) and events (e.g., authentication)” thenΒ expand.
  • β€œFocus on Use Cases: SIEM requirements should be driven by specific problems the organization wants to solve, such as tracking unauthorized access or detecting web application hacking.”
  • β€œTuning Ability: The organization must accept responsibility for customizing and tuning the tool, as β€œout-of-the-box” SIEM deployments rarely succeed.”

All of the above are from the early to mid 2000s. These also aged well, despite being almost ΒΌ of a centuryΒ old…

Lessons? So what does it mean that advice from 2003 still works in 2026? A few uncomfortable lessons:

  1. SIEM problems were never technology problems. They wereβ€Šβ€”β€Šand are, and perhaps will beβ€Šβ€”β€Špeople, process, and organizational physics problems wearing a technology costume. This is why 23-year-old advice still applies: the vendors shipped new tech, but nobody shipped new organizations.
  2. The β€œwhat” aged well; the β€œhow” got replaced. Output-driven collection, phasing, use cases, context, tuning ownershipβ€Šβ€”β€Šall still true. What changed is the plumbing: appliances became data lakes, EPS became tokens, correlation rules got a non-deterministic AI sidekick. If your strategy changes every time the plumbing changes, you never had a strategy. Good news!?Β Yes!
  3. Cost pain is eternal; only the currency changes. In 2003 you ran out of hardware, in 2015 you ran out of ingest budget, in 2026 you run out of tokens. β€œSIEM costs kill” is apparently a law of nature, so architect for it (output-driven!) rather than being surprised by it.Β Again.
  4. If the advice didn’t change, but you still don’t follow it, the advice was never the problem. Everyone β€œknows” to plan the deployment, start with use cases, and own the tuning. Knowing isn’t the bottleneck. Doing is. AI won’t fix that eitherβ€Šβ€”β€Šit will just help you not-do itΒ faster.
  5. The industry has a roughly 7-year memory. Every cycle, β€œnew” best practices get rediscoveredβ€Šβ€”β€Šat $xxx/hour consulting ratesβ€Šβ€”β€Šby people who could have read my 2005 SlideShare for free. Reading old stuff is the cheapest security investment you’ll make thisΒ year?

So no, I’m not prescient. The organizations are just slow (as I said after leaving Gartner: β€œIT inertia is the most powerful force in the Universe”). We had 23 years of progress, and the best practice is still β€œhave a plan and don’t ingest garbage.” See you in 2043, when this post ages wellΒ too…

Related posts:


The Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026 was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.

Digitale borden op treinstations zijn leeg door storing bij NS

13 August 2026 at 20:38
De NS heeft last van een storing in zijn reisinformatiesysteem. Daardoor zijn de digitale borden op treinstations leeg en kan er geen informatie worden omgeroepen. Het is niet bekend hoelang de storing nog duurt. De treinen rijden wel volgens de normale dienstverlening. De NS-app lijkt ook ongeschonden.

Qualcomm stopt acht Arm-cores in Snapdragon C-processor voor budgetlaptops

13 August 2026 at 20:28
Qualcomm deelt voor het eerst concrete details over zijn Snapdragon C-cpu. Die Arm-cpu moet gebruikt worden in laptops vanaf 300 dollar, claimt de cpu-maker. De chip krijgt acht cpu-cores en ondersteunt maximaal 16GB ram. De eerste Snapdragon C-laptops verschijnen 'binnenkort'.

Ransomwarebende Clop claimt Shell en Philips te hebben gehackt

13 August 2026 at 19:43
Clop, een Russische ransomwarebende, claimt Shell en Philips te hebben gehackt. Bij de hack zouden onder andere technische tekeningen gestolen zijn. Beide bedrijven laten inmiddels weten dat zich inderdaad een incident heeft voorgedaan.

AI 'watermark removers' flood the web. Almost none can prove they work.

13 August 2026 at 19:33
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

Meerdere kwetsbaarheden in Autodesk AutoCAD

Er zijn meerdere kwetsbaarheden gevonden in Autodesk AutoCAD. AutoCAD is een softwareprogramma voor het maken van technische tekeningen. De kwetsbaarheden met CVE-2026-16463 (score 7.8), CVE-2026-16465 (score 6.1) en CVE-2026-17550 (score 5.5), zijn door ons beoordeeld als middelmatig qua kans op misbruik en hoog qua mogelijke schade.

Bambu Lab kondigt in september R1-lasergraveermachine aan

13 August 2026 at 18:41
Bambu Lab komt binnenkort met zijn eerste lasergraveer- en snijmachine: de Bambu Lab R1. Die moet gebruikers helpen om dingen te maken 'met meer verschillende materialen'. Het bedrijf deelt nog weinig concrete details, maar zegt het apparaat in september te onthullen.

Keychron C100 8K-macropad heeft 100 programmeerbare knoppen voor 65 dollar

13 August 2026 at 18:01
Keychron komt met een nieuwe macropad: de C100 8K. Het is een soort leeg toetsenbord met 100 knoppen, die gebruikers helemaal zelf kunnen instellen. De C100 8K heeft een rgb-verlichting op iedere toets en een draadloze verbinding. Hij kost 65 dollar in de VS; de europrijs is niet bekend.

Europese privacytoezichthouder ziet risico's in uitbreiding bevoegdheden Europol

13 August 2026 at 16:09
De Europese privacytoezichthouder EDPS is bezorgd over de geplande uitbreiding van bevoegdheden voor Europol. Volgens een EC-voorstel mag die Europese politiedienst straks ook persoonsgegevens verwerken van mensen zonder gevestigde criminele banden. De EDPS ziet ernstige risico's.

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

13 August 2026 at 16:00
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
❌