Alex Teixeira
Oct 4, 2024

--

Hey Tho, it's not easy to highlight or detail all features w/o writing a whole book chapter.

Happy to have a quick call with you but I can tell you RBA requires more effort for both implementation (requirements) and maintenance.

Besides, troubleshooting is harder and you have less flexibility to implement some 'features' since you rely on the vendor.

If you start customizing to your needs, you better consider building your own which makes things simpler and less ES-upgrade-sensible, if you know what I mean...

Hope that helps!

--

--

Alex Teixeira
Alex Teixeira

Written by Alex Teixeira

I design and build detection and SIEM/EDR/XDR content for Enterprise #SecOps teams #DetectionEngineering http://opstune.com

No responses yet