Cloud-Native SIEM Model – Jonah Kowall, Logz.io
Jonah Kowall, CTO at Logz.io, talks with Alan on a number of trends related to the observability and security industries. Jonah dives into the current cloud-native SIEM model, how it is broken, and how a modern approach to SIEM leads to more agile SecOps. He also discusses the role that the true cloud-native SIEM plays in solving the “security poverty line”, while making the job of the modern SOC team easier. Then, he gets real about DevSecOps and addresses the confusion and overhype around it.
Transcript
This is texturing TV. Hey everyone, welcome to another text junk TV interview. I am happy to have back on the show my scuba diving globetrotting observability open source security.
Aficionado Jonah cow when he's not doing all of those things Joni's the CTO over logs. Hey Jonah welcome. Thanks a lot.
Appreciate you having me on always great to catch up. Absolutely. So just to take care of a little personal business you just got back from is it Dominica right where you went on a little scuba vacation?
Yeah Dominica. It's a small Caribbean island in the kind of the French islands over there. It's pretty unpopulated unspoiled and Yeah, nice little place to visit for sure.
Cool. Hope you had a great time. Jonah we you know, I want to jump into stuff.
But before we do we yeah in case anyone out here is not familiar with logs. You want to give them a quick kind of background? Yeah, definitely.
So logs IO is a cloud observability company. We started out being basically the posted scalable elk stack for logging. We've expanded we built a Sim on top of that.
So we have a security product that's been out for close to three years and more recently. We built metrics product based on Prometheus and a tracing product based on Jager. So we're very open source Centric extremely high scale platform and we really just make it easy to run open source that your team's already love and know, you know more easily across the organization, so That's what we do as long as you mentioned.
We might as well mention. You're also very involved with the Yeager project and cncf. Yeah, we work in a few different communities.
The big one is open search which we worked along with AWS on that is an open source version of the elk stack because that's now proprietary in the other is Yeager with the cncf for those of you that are going to cubecon. I'll be doing the Yeager maintain or talk with one of the other maintainers but we built quite a few interesting things in Yeager over the last year and a half and the projects definitely been evolving more towards an APM tool versus just a tracing in trouble shooting tools. So it's definitely getting better and everything we do is in the open source, you can use it today with Prometheus and Yeager together, so Actually, and just for anyone wondering out there a kubecon is coming up.
I I think it's in October. It's in Detroit Rock City this year a hard getting hotels there already. So if you're planning are going to coupon cubecon go make your hotel reservation sooner than later Jonah.
Thank thanks for the background. Wanted to talk today about Sort of the unwritten connection, or maybe it's a written connection or maybe someone has a Blog coming out about it, but between observability and security right A lot of people say well, you know observability is observability. It reminds me of the old saying right.
All spaghetti is macaroni, but not all macaroni is spaghetti. right security is inherently attached to observability and there's there's obvious security implications of of observe, you know in doing observability. However, observability could be more than just security, you know, I think obviously as well, but yeah, you're the expert Talk tie it up for us Jonah.
Yes. So the when you go back a little bit. Security teams are very different than operations teams who used to be different than development teams.
And now we've kind of brought together development and operations and to devops, but we still have security that separate. and so the challenge now is because of continuous release where we're pushing and to production constantly security now has to be embedded into that process of automation because you can't keep up with the rate of change if you try to do it manually or you're dealing with it after that. So, you know as you've heard from many companies and vendors on on your digital properties over the last few years devops has been this big push of like injecting security into devops.
And how we converge the teams, but I think the fundamental change that needs to happen, which is probably going to take many many years as how do we get these teams better integrated, but shorter term how do we educate devops teams on the things that they need to pay attention to during their day-to-day work and it's a big challenge for security teams that are usually a minuscule portion of the size of the devops team. So it is I mean and so one of the ways of scaling that of leveraging. You know, the the limited resources of security teams is software tools, right?
It was like blogs. Where you know where we're taking these observability? tools that you know, the Ops and devops teams are familiar with and and bring it not that the security functionality was never there because one may argue that Sims.
Yeah, she's a clear security tool was really a logs collector observability tool forever, but we're taking those. those security angles if you will right and bringing them. You know front and center in a way that devops teams.
Can use them can more easily digest them. They make more sense to them if you will Fair. So we sell like our security products more to security teams and are observability tools to observe ability teams.
The interesting thing is that if I go back six months, we only had a handful of customers that were actually using both together because the budgets are different the teams are different. They have different requirements. They they like the fact that their security tools speaks a security language and that they're observability tools speaks more of a software engineering language in terms of the UI and what things are called and how you deploy it.
So it's it's definitely a challenge to bring them together, but now as companies are scrutinizing the number of vendors and how much they're paying and they realize that by combining the use cases on both sides. They can actually reduce their spend on both sides because you don't need to collect the data twice send it twice store it twice pay for it twice. Probably 30% of the data overlaps 70% of it is developers don't need firewall logs.
Right similarly security teams don't need all of the application debug logs. So there is definitely separate data sets that either team needs but there's a lot of commonality in between too. So, so do you see logs selling?
A unified product if you will. For organizations that think that way and usually it's what I would call. Once the company gets big enough to where they need a SIM.
Usually it's like 400 people or so that you sort of start thinking about. Oh, I have too much data, and I need to correlate it. That's usually where it starts and then as the the company kind of starts to think about the way that they manage security up to, you know, a couple of thousand people they see efficiencies in bringing it together when you get to really large Enterprises these budgets and silos become like way bigger and more complicated.
So I don't see the convergence on our really large Enterprise customers, even though there's a couple of Exceptions there. But in that sweet spot where it's like a thousand employees somewhere around there, you know attack company security often rolls into the CTO the same way that devops teams and software engineering teams do and the the CTO will often say you guys have to work better together. Let's solve this problem.
And and kind of push towards doing something that's more uniform so that they can have a commonality between the different teams. Your journey I go back to my time when we still secure a company. I help I co-founded and and we it was vulnerability management network access control.
We had intrusion prevention, but we had this concept of dashboards, right and that dashboard views were different right? It's security admin, you know, it was deep in the bows of Of vulnerability scanning had a very different dashboard than the CIO did or the CSO, you know an executive team did a manager had a different dashboard than a doer a single video Single practitioner kind of person. I mean, I foresee a similar thing here where look you have this body of data that you're collecting.
What slice of it you want and how you want it displayed. That's for smart software developers to come up with the right views for the representatives. Yeah, a lot of what SIM is is actually content.
So we have a team of security analysts at our company that build content and integration so that when you send data from your Palo Alto firewall, we've got all the rules the best practices the dashboards the views that the security team expects to see Um that happens a little less in devops where packaged content isn't as popular in general. I mean, it's still somewhat useful for big things like kubernetes or Kafka or things that we deploy but in security content is King like we ship I think about 600 out of the box dashboards we deal with the rules. What are the best practices of dealing with that data?
What should I be alerted on a lot of what the Sim is is actually content honestly and and a handful of features that we built on top. But the content is really what people expect because when they send the data they want it to be parsed and normalized and you want to get alerts and you want those dashboards so that you can make sure that you're looking at the right thing. a great very cool I mean that's that's certainly a big trend.
Around observability and sin, but you know what? I mean for instance tomorrow. Well by the time people see this it'll be passed tomorrow, but August 10th, we we were doing we're doing a virtual event Cloud native day.
And when we look at the mega Trends around driving Cloud native, I mean obviously kubernetes is still kubernetes, right? No one's saying no, but the whole observe ability piece of it around Prometheus and and lights that and some of the other just huge projects data collectors if you will. Then a driving observability continue.
You know High trajectory growth and everything else Jonah. Where did I mean? Where does it end?
Is there a peak? What do you think? Um, there's always more data that's useful.
So right now an open Telemetry, which is the big data collection project. It deals with logs metrics traces. These are kind of the foundational pieces, but the projects hard at work on the next data set which is profiling so profiling helps a lot with troubleshooting complex problems and gives you an extra layer of visibility and I expect that there's going to be more and more signals that we're going to bring in to open Telemetry that then we're going to have to deal with on the back end in terms of analyzing it visualizing it providing the insights into the data.
So I don't think there's ever going to be really an end to the data and similarly. I think over time we're going to have new use cases built on top of the Telemetry data. So kind of what we're doing right now with our Sim I think is is gonna evolve considerably in terms of the way that we bring together both of those views for teams that start to be more cross-functional.
So I think the You know, the the projects in general are going to continue accelerating in terms of different data sets and there's lots of good Innovation that's happening out there in the communities that are going to unlock new ways of analyzing and collecting data too. So, I think there's a lot more to come for sure and a lot of exciting entrepreneurs out there building some of the next gen stuff that you know, hopefully will be well adopted in the coming years, so Very cool. Yeah.
All right. Hey Jonah, we're about at a time. But thanks for stopping in good.
You kind of globetrotting. You know, we got you for a minute here at home in Florida. Stay in touch with us.
If nothing else will certainly see you a cubecon, but maybe we'll touch base before then. Sounds great. Looking forward to Detroit.
Definitely. io, right? It's hello gz that I oh, yeah, people want to get up your game.
It's hard to read the logs there Jones. I know it's really small. And also we have the open observability podcast.
You can find on YouTube where we talk to open source Centric projects and leaders. So, yeah, it's it's always great. All right.
Johnny Kyle logs IO here on Tech Strunk TV. We're gonna take a break and we'll be back in just a moment.