Blumira Automated Detection & Response

Blumira's Automated SIEM enables organizations to detect and respond effectively to cybersecurity threats without having a dedicated in-house security operations center or security expertise.

Languages supported: English

9.6/10 (Expert Score) ★★★★★
Product is rated as #4 in category and Response (SOAR) Software
Ease of use
9.4
Support
9.5
Ease of Setup
9.5

Images

Check Software Images

Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more efficiently defend against cybersecurity threats in near real-time. It eases the burden of alert fatigue, complexity of log management and lack of IT visibility.

Blumira’s cloud SIEM can be deployed in hours with broad integration coverage across cloud, endpoint protection, firewall and identity providers including Office 365, G Suite, Crowdstrike, Okta, Palo Alto, Cisco FTD and many others

Blumira Automated Detection & Response
Blumira Automated Detection & Response

Show more categories

Customer Reviews

Blumira Automated Detection & Response Reviews

Administrator in Electrical/Electronic Manufacturing

Advanced user of Blumira Automated Detection & Response
★★★★★
strong incident detection and response capability

What do you like best?

Blumira's strength is in their creation of high quality detections known as "findings" in the blumira dashboard. They are constantly improving the product by adding new finding types to respond to the latest threats. The step by step workflows that walk you through how to respond to each finding when it is received are very helpful especially for teams that do not have establised in house security teams or incident response capabilites.

What do you dislike?

While the detection and response capabilities are great, blumira's weakness is in generic log search and threat hunting through existing logs. The provided log search tools make discovery of column names and relevant information difficult when compared to the UI of other platforms such as ELK, and humio. Still, if your primary goal is real security and not digging through logs, blumira has an excellent product. Another area that could be improved is the onboarding process for getting up and running with high signal log sources. It would be easy to miss the value of blumira if GPO audit settings, linux syslogs, sysmon, and other sources are not properly configured for good coverage.

Recommendations to others considering the product:

If your current SIEM solution only does logging and generates reports, consider switching to Blumira to upgrade to real detection and response capabilites.

What problems are you solving with the product? What benefits have you realized?

Blumira provides the important SIEM corner of the SOC Visability Triad. It gives peace of mind that there is an additional layer of protection beyond basic EDR and leverages SIEM as a detection tool due to the valuable findings .

Review source: G2.com

Leave a reply

Your total score

B2B Software Guide