An in-depth view of reporting
With a much clearer view of automation, it’s now time to shift our focus to reporting and its role in SOAR. Reporting is not a new tool and is not strictly connected to SOAR. All SIEM solutions have their own variation of reporting. In most cases, SIEM reporting is more about visualizing the huge amount of data that is being ingested, while in SOAR, it’s mostly about reporting on incidents, automation, and overall SOC performance.
While most SIEM and SOAR solutions are still separated into their own spaces, some SIEM and SOAR tools are integrated, such as Microsoft Sentinel, and SIEM and SOAR use the same reporting mechanisms.
We can expect this to be the case more and more, and the line between SIEM and SOAR will likely, and should, disappear. This unification of SIEM and SOAR will bring easier management and integration of services, such as reporting, where we will have better overview and management, as well as fewer portals for...