https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Getty Images

Sponsor Content

sdr xdr siem platforms

How XDR Differs from SDR, SIEM and Platforms

  • Written by Trend Micro Guest Blogger
  • May 21, 2020
The distinctions among XDR, SIEM and platforms make for a very big, very real, and very pragmatic deal of difference.

In Jon Clay’s post, he does a great job of explaining the evolution from EDR to XDR. In short, he explained that Endpoint Detection and Response (EDR) is great, but that having sources of information beyond endpoint is better. The “X” in XDR is essentially “many” or whatever we can add to provide a broader, better source of detection and response.

So that is how XDR is different from EDR.

A common and healthy initial reaction to XDR should be, “This sounds a lot like SIEM and platforms: many things feeding into a single collector.” Allow me to explain the differences, and why these differences make for a very big, very real, and very pragmatic deal of difference.

Let’s look at SIEM. A lot of rocks get thrown at SIEM, but SIEM is awesome considering what it is being asked to do—pull log data from dozens or hundreds of vendors’ products and then try to make sense of them to produce meaningful alerts.

SIEM, however, is wide yet shallow. It collects from a lot of things, but the information it collects is very limited. SIEMs can’t force a specific product class, such as an endpoint protection platform (EPP), to cough up more information than the generic, agreed-to-upon format allows. And when that EPP adds some new proprietary inspection features, the SIEM is highly limited as to when and how it could add those new data feeds.

And the big factor of SIEM is that SIEM has no R in it—that is, there is no inherent response built into SIEM. It’s a detection tool, a fire-alarm that isn’t connected to the sprinklers. But across so many products from so many vendors, SIEM is still and will continue to be valuable, and is not replaced by XDR. In fact, with XDR it can be even more valuable.

What about vendors that provide a lot of products across multiple categories–those that are supposed to have exchange and correlation richer than SIEM’s, and include response. Isn’t that what platforms are? How is XDR different from that?

Platforms have fallen short for a few reasons. The foremost reason platforms haven’t done the job is that they don’t have an independent collector or data lake.

I’ve been preaching about “glue between the silos,” for years but it’s still silos.There is signaling between the elements, and the consoles for the elements have had the analysis built in. This is weak for two reasons: Consoles are for a specific organization role (for example, EPP is for endpoint security ops), and the integration for that role is not enterprise-wide.

Here’s what I mean. If that EPP pulls in useful info from an IPS, that is usually helpful specifically to the EPP analysts. But what if that resultant information would be even more useful to

  • Page 1
  • Page 2
Tags: MSPs Digital Transformation From the Industry Intelligence Security Technologies Trend Micro Sponsor Content

Most Recent


  • Bankruptcy Court
    Avaya Reduces Debt by $2.6 Billion, Gets Closer to Emerging from Bankruptcy
    The company will be backed by its existing lenders.
  • Twenty, 20
    The CF List: 2023's 20 Top Threat Intelligence Providers You Should Know
    The appetite for threat intelligence continues to grow. See who made our list and why.
  • Welcome Mat
    Granite Taps Viasat, Mavenir Vet to Strengthen Western Channel Sales
    He brings a ton of channel experience.
  • Word subscribe on a computer monitor
    Channel Partners Struggle in Shift to Subscriptions
    Seventy-eight percent of channel partners have “more to do” in their move to services and subscriptions, says a new report.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • 5G
    5G: Revolution or Evolution?
  • M&A
    Why All MSPs Need to Understand the M&A Landscape
  • hurricane season
    4 Things MSPs Should Consider When Prepping for Hurricane Season
  • zero-trust
    The Benefits of Zero-Trust Security over VPNs

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

The CF List: 2023’s 20 Top Threat Intelligence Providers You Should Know

March 22, 2023

Lumen Channel Leaders: Activation Incentives ‘Resonating’ with Partner Community

March 21, 2023

Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More

March 21, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

The new @TDSYNNEX directory will include exclusive and premium benefits for CommunitySolv members.… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

Tim Mueller with @mw_advisors provides useful strategies for selling your MSP #channelpartners #msp #technews… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

"...everybody that's ever influenced me in my life has been somebody that's been willing to listen..." 📺 Hear from… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

Our latest #CFList includes top #threatintelligence providers, with @CrowdStrike, @kaspersky, @Microsoft,… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

🤔 What if we told you that DE&I could help you stay competitive and propel your business forward? Join us on April… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

In recent months, @cytracom appointed a 30-year industry veteran, formerly with Level Platforms and CompTIA, as cha… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@SolutionsLg rolls out expanded LG Pro Channel Partner Program for U.S. resellers. dlvr.it/SlGPYg https://t.co/lzWGCZsNc8

March 21, 2023
ChannelFutures

When it comes to cybersecurity 🔒, these 20 leaders represent the future of the channel. Who do you think made the l… twitter.com/i/web/status/1…

March 21, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X