Evaluate The Security Operations Company Symantec On Security Information And Event Management [patched] -
If your primary use case is PCI-DSS compliance (90 days of log retention on 500 systems) or parsing cloud SaaS logs (Office 365, Salesforce, Okta), look elsewhere. Symantec’s log ingestion is expensive and cumbersome compared to native cloud SIEMs. It is a tool, not a log-first tool.
Unlike legacy SIEMs built primarily for log aggregation, Symantec Security Analytics was built for and network forensics. This changes the evaluation criteria: If your primary use case is PCI-DSS compliance
If you are a full Symantec shop (SEP, DLP, CASB, Proxy), the SIEM provides remarkable correlation. For example, it can link a malware detection on an endpoint with the network session that downloaded the payload and the DLP alert that fired when data left. This kills alert fatigue. If your primary use case is PCI-DSS compliance






