Skip to content

Commit bba6f83

Browse files
authored
Merge pull request #269 from VirtualMetric:DT-445-updates-proof
DT-445-updates-proof
2 parents b1649f3 + ac29b83 commit bba6f83

File tree

4 files changed

+749
-639
lines changed

4 files changed

+749
-639
lines changed

docs/about/siem-optimization.mdx

Lines changed: 5 additions & 54 deletions
Original file line numberDiff line numberDiff line change
@@ -55,35 +55,9 @@ Key principles include:
5555

5656
AI-based approaches introduce multiple risks that VirtualMetric's deterministic framework eliminates. AI models require training on actual log data, creating privacy and compliance concerns as sensitive security information may be learned by the model. AI processing adds significant latency and computational cost, reducing throughput and increasing infrastructure requirements. Most critically, AI decisions cannot be audited or validated, making it impossible to verify that security-relevant data is preserved.
5757

58-
```mermaid
59-
graph TD
60-
subgraph AI[AI-Based Optimization Risks]
61-
R1[Unpredictable Results]
62-
R2[May Drop Critical Events]
63-
R3[Privacy Concerns]
64-
R4[Training on Sensitive Data]
65-
R5[Processing Latency]
66-
R6[Increased Costs]
67-
R7[Non-Auditable Decisions]
68-
end
69-
70-
subgraph VM[VirtualMetric Approach]
71-
V1[Deterministic Rules]
72-
V2[Guaranteed Field Preservation]
73-
V3[No Data Learning]
74-
V4[High Performance]
75-
V5[Cost Efficient]
76-
V6[Fully Auditable]
77-
V7[Expert Validated]
78-
end
79-
80-
AI -.->|Risk| Enterprise[Enterprise Security]
81-
VM -.->|Safe| Enterprise
82-
83-
style AI fill:#FFE5E5
84-
style VM fill:#BCC0E7
85-
style Enterprise fill:#E5E2FB
86-
```
58+
|AI-Based Optimization (Risky)|VirtualMetric's Approach (Safe)|
59+
|---|---|
60+
|<ul><li>Unpredictable Results</li><li>May Drop Critical Events</li><li>Privacy Concerns</li><li>Training on Sensitive Data</li><li>Processing Latency</li><li>Increased Costs</li><li>Non-Auditable Decisions</li></ul>|<ul><li>Deterministic Rules</li><li>Guaranteed Field Preservation</li><li>No Data Learning</li><li>High Performance</li><li>Cost-Efficient</li><li>Fully Auditable</li><li>Expert Validated</li></ul>|
8761

8862
**DataStream**'s expert-driven approach provides predictable, consistent results that security teams can trust. Every optimization decision is based on analysis of real-world security operations, validated by experts, and documented for audit purposes. Organizations can confidently deploy aggressive optimization knowing that detection capabilities remain intact.
8963

@@ -104,7 +78,7 @@ Advantages over AI-based optimization include:
10478
This approach means administrators configure optimization rules once per vendor, not once per vendor per SIEM platform. A single Fortinet optimization pack automatically reduces data volume for Sentinel, Splunk, Elasticsearch, and all other configured destinations. Changes to vendor-specific filtering rules immediately apply across the entire multi-platform deployment.
10579

10680
```mermaid
107-
graph TD
81+
graph LR
10882
Vendor[Vendor Logs] --> Pack([Vendor Optimization Pack])
10983
11084
Pack --> Optimized[Optimized Data]
@@ -146,30 +120,7 @@ graph LR
146120
Logs[Vendor Logs]
147121
148122
subgraph Packs[Vendor Optimization Packs]
149-
FN[Fortinet]
150-
PA[Palo Alto]
151-
CP[Check Point]
152-
CS[Cisco]
153-
ZS[Zscaler]
154-
CT[Citrix]
155-
FP[Forcepoint]
156-
F5[F5 BigIP]
157-
SW[SonicWall]
158-
BC[Barracuda]
159-
IB[Infoblox]
160-
WG[WatchGuard]
161-
NZ[Nozomi]
162-
AK[Akamai]
163-
EH[ExtraHop]
164-
DT[Darktrace]
165-
CA[CyberArk]
166-
VC[Vectra]
167-
CR[CrowdStrike]
168-
SM[Symantec]
169-
SO[Sophos]
170-
JN[Juniper]
171-
AR[Aruba]
172-
S1[SentinelOne]
123+
PEnt["`Fortinet<br>Palo Alto<br>Check Point<br>Cisco<br>Zscaler<br>Citrix<br>Forcepoint<br>F5 BigIP<br>SonicWall<br>Barracuda<br>Infoblox<br>WatchGuard<br>Nozomi<br>Akamai<br>ExtraHop<br>Darktrace<br>CyberArk<br>Vectra<br>CrowdStrike<br>Symantec<br>Sophos<br>Juniper<br>Aruba<br>SentinelOne`"]
173124
end
174125
175126
Logs --> Packs

docusaurus.config.ts

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -92,10 +92,9 @@ const config: Config = {
9292
[
9393
require.resolve("docusaurus-lunr-search"),
9494
{
95-
excludeRoutes: [
96-
"/1.*/**/*",
97-
],
98-
},
95+
excludeRoutes: ["/1.*/**/*"],
96+
disableVersioning: true,
97+
}
9998
],
10099
require.resolve('./plugins/validate-topics'),
101100
require.resolve('./plugins/validate-images'),

0 commit comments

Comments
 (0)