Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security data fabric versus SIEM: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Many SOCs now need a hybrid security data fabric because SIEMs struggle with cost, scale, and cloud-native telemetry, while data lakes lack native real-time detection and require stronger governance, according to DataBahn. The real shift is architectural: enrichment, routing, and retention decisions must happen before ingestion, not after it.

NHIMG editorial — based on content published by DataBahn: Security data fabric architecture for SIEM and data lakes

Questions worth separating out

Q: How should security teams design a hybrid SIEM and data lake architecture?

A: Start by deciding which telemetry must support immediate alerting and which must support long-term analysis.

Q: When does a security data lake create more governance risk than value?

A: A lake becomes risky when it stores sensitive telemetry without access controls, classification, or ownership.

Q: What do teams get wrong about reducing SIEM costs?

A: They often try to cut cost after ingestion instead of deciding what should be ingested in the first place.

Practitioner guidance

  • Define routing policy before ingestion Classify events by detection value, forensic value, and retention requirement before they enter the SIEM or lake.
  • Preserve identity context at the edge Attach user, service account, workload, and environment metadata during collection so downstream correlation does not depend on guesswork.
  • Separate detection ownership from retention ownership Assign the SOC ownership of alerting logic and the data platform team ownership of storage tiers, normalization, and replay.

What's in the full article

DataBahn's full article covers the operational detail this post intentionally leaves for the source:

  • Detailed explanation of how the hybrid pipeline separates collection, routing, and storage decisions
  • Step-by-step examples of when telemetry should stay in the SIEM versus move to the data lake
  • Operational trade-offs around normalization, tiered retention, and unified analytics
  • Why enrichment before ingestion changes both detection quality and SIEM economics

👉 Read DataBahn's analysis of security data fabric architecture for SIEM and lakes →

Security data fabric versus SIEM: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Security data fabric is becoming the pragmatic answer to telemetry sprawl. The old assumption that one central SIEM can both detect threats and absorb every raw event no longer holds at enterprise scale. Data fabrics separate detection from retention, which is the only way to preserve investigative depth without forcing every byte through the same expensive control point. Practitioners should stop treating SIEM replacement as the question and start treating data routing as the governance issue.

A question worth separating out:

Q: What accountability issues arise when telemetry is split across SIEM and data lake?

A: Teams can lose clarity over who owns detection, who owns retention, and who approves access to historical evidence. The answer is to assign explicit operational ownership to each layer and document which records are security logs, investigative records, or compliance archives.

👉 Read our full editorial: Security data fabrics are changing how teams balance SIEM and lakes



   
ReplyQuote
Share: