The Golden Throne: Stop Blindly Flushing
Most folks build their SIEM the same way they load a junk drawer: by shoving in whatever they already have—Active Directory, firewalls, and a whole lot of “eh, why not.” But at Graylog, we think you deserve better than a glorified log toilet. In this talk, we’ll flip the script: start with the problems you’re actually trying to solve, then figure out what you need to know, then what data supports that. And with Graylog’s Intelligent Data Routing, you can now act on that plan—sending high-value data to hot storage and archiving the rest to standby storage for when (and if) it’s needed. Build your SIEM like it has a brain—and a budget. 0:00 Introduction & Session Overview 0:47 The "Golden Throne" Concept: Stop Blindly Flushing Logs 1:29 The Problem with the Log Toilet Approach 2:50 A Better Way: Start with Business Risks 4:46 Step 1 – Define the Context You Need 6:55 Step 2 – Detection: Knowing When Something Is Wrong 9:14 Step 3 – Triage: What Analysts Need to Investigate 14:12 Step 4 – Identifying Your Data Sources 16:34 Step 5 – Prioritizing Data Ingestion & Storage Strategy 20:53 Why This Approach Matters: Cost, Value & Effectiveness