Google SecOps a replacement for legacy SIEM
Use Cases and Deployment Scope
Google Security Operations actually replaces our company old SIEM solution. The new UDM feature actually changes the way anyone can query the logs and get high quality co-relation.
Pros
- UDM model, makes use of co-relation across various field.
- The UI is quite nice and easy to understand.
- The search throughout is high which makes it easy to query and get results.
Cons
- The alert page is very underdeveloped as compared to other solutions.
- The page which handles automation UI is also very hard to understand.
Likelihood to Recommend
If you have lots of log sources across different solutions. Then UDM co-relation is a game changer and well suited for you. IF you close and document all the incident report in SIEM then it's not good for you.