SIEM Vendor Demo Script

Author(s): Wesley McPherson , Filipe De Souza

This template is designed to provide Security Information & Event Management (SIEM) vendors with a consistent set of instructions, ensuring an objective comparison of product features – all while evaluating ease of use, and ease of setup and configuration.
The template is pre-built with five common scenarios to leverage:
  • Log source configurations
  • Event correlation, alerting, log analysis, and incident management
  • Reporting features
  • Dashboard and access control features
  • Data management
  • Full threat visibility
  • Scalability

Vendor demonstrations are essential in order to evaluate SIEM user experiences. Allowing vendors to run the demonstration without your guidance will only highlight their strengths.