Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Legacy SIEMs and telemetry pipelines: what should CISOs change now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Legacy SIEMs create cost, latency, and context problems because ingestion scales faster than security value, and DataBahn argues that pre-SIEM pipelines, upstream enrichment, and open schemas can reduce noise while making telemetry usable for detection and AI-driven operations. The architectural shift matters because security data now has to be governed before it reaches analytics layers, not after.

NHIMG editorial — based on content published by DataBahn: Why are Legacy SIEMs a problem?

By the numbers:

Questions worth separating out

Q: How should security teams reduce SIEM noise without losing important alerts?

A: Focus on context, not volume.

Q: Why do legacy SIEM architectures struggle with modern cloud and identity data?

A: Because they assume a stable log structure and a centralised processing model.

Q: What do security teams get wrong about GenAI in the SOC?

A: They often assume the model reduces the need for analyst judgment.

Practitioner guidance

  • Map telemetry control points before SIEM ingestion Inventory where logs are collected, enriched, filtered, and routed, then document which decisions happen at each stage.
  • Move enrichment to the edge and stream layers Attach asset, identity, and risk context as close to collection as possible so that downstream tools receive already-classified events.
  • Adopt open schemas for reusable telemetry Standardise event structure with a schema that can support detection, investigation, and compliance without repeated transformation.

What's in the full article

DataBahn's full blog covers the operational detail this post intentionally leaves for the source:

  • Specific implementation guidance on pre-SIEM routing and enrichment design choices.
  • The mechanics of agentic AI automation across parsing, schema detection, and delivery decisions.
  • Operational detail on reducing ingestion cost without losing investigative fidelity.
  • The company’s framing of how its pipeline model is intended to support future AI use cases.

👉 Read DataBahn's analysis of legacy SIEM limits and security data pipelines →

Legacy SIEMs and telemetry pipelines: what should CISOs change now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Legacy telemetry sprawl is now a governance problem, not just an operations problem. Security teams are still treating ingestion, enrichment, and storage as downstream hygiene tasks, but that model breaks once data volumes, vendor churn, and source complexity scale. A SOC cannot trust what it cannot contextualise, and IAM and NHI signals become far less useful when they are delayed or stripped of meaning. The practical conclusion is that telemetry governance now belongs in the security architecture conversation.

A question worth separating out:

Q: Should organisations replace SIEMs with security data pipelines?

A: Not necessarily. The better model is to stop treating the SIEM as the centre of the architecture and use the pipeline to decide what should be seen, stored, or suppressed. SIEMs still matter for correlation and investigation, but only after telemetry has been made usable upstream.

👉 Read our full editorial: Legacy SIEMs create telemetry sprawl and AI readiness gaps



   
ReplyQuote
Share: