AWS Security Lake


Taking a look at this new AWS Security Lake which was announced at re:invent 2022 and wanted to get peoples thoughts & opinions on what was announced.  Do you see it as potentially useful in your day to day or do you think it's just another money grabbing scheme in the name of security?

While I'm still on the fence about the whole thing (just re-watching the re-invent presentation), I think the creation of the Open Cyber Security Framework (ocsf) is a positive.


I also like the idea of keeping your data a bit closer to you, instead of sending a copy of all data you want to include for analysis over the network to a SIEM solution.

It's going to be interesting to see how big SIEM vendors will adopt to this. I'm sure some of them really like the money they make by charging for all the data you ingest into their SIEM solution. They may need to rethink their pricing model... 

