Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

Gestión de SIEMSIEM Management

Splunk, QRadar, Sentinel, Elastic.Splunk, QRadar, Sentinel and Elastic.

SIEMSIEM 3.3 · Servicios Gestionados de Plataformas3.3 · Managed Platform Services

¿Qué es este servicio?What is this service?

Es la operación diaria de la plataforma SIEM de la organización —Splunk, QRadar, Sentinel, Elastic— por parte de un equipo externo: mantener las fuentes conectadas, los parsers al día, las reglas vivas, la retención cumplida y el volumen de ingesta bajo control.

The day-to-day operation of the SIEM platform — Splunk, QRadar, Sentinel, Elastic — by an external team: keeping sources connected, parsers current, rules alive, retention met and ingestion volume under control.

¿Para qué se usa?What is it used for?

Sirve porque un SIEM se degrada solo. Una fuente deja de enviar y nadie se entera hasta que hace falta ese registro en una investigación; un cambio de formato rompe el parser y la regla que dependía de ese campo deja de disparar en silencio. Además está el costo: la mayoría de las organizaciones paga por ingerir gigabytes que nadie consulta jamás.

It matters because a SIEM degrades on its own. A source stops sending and nobody notices until that log is needed in an investigation; a format change breaks the parser and the rule depending on that field silently stops firing. Then there is cost: most organisations pay to ingest gigabytes nobody ever queries.

Qué beneficios traeBenefits it delivers

  • Vigila la salud del propio SIEM: fuentes caídas, colas atascadas, parsers rotos. Es el punto ciego clásico.
  • Controla el costo de licenciamiento por volumen, que suele ser la partida más cara y la peor gestionada.
  • Mantiene las reglas al ritmo del entorno: cada servidor nuevo o migración a la nube cambia lo que hay que vigilar.
  • Garantiza que la retención acordada se cumple de verdad y que los datos son consultables cuando hacen falta.
  • Watches the health of the SIEM itself: dead sources, stuck queues, broken parsers. The classic blind spot.
  • Controls volume-based licensing cost, usually the most expensive line item and the worst managed.
  • Keeps rules in step with the environment: every new server or cloud migration changes what needs watching.
  • Ensures the agreed retention is genuinely met and the data is queryable when needed.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de tener un SIEM en Costa Rica.
  • El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE capacidades de monitoreo, y su artículo 42 obliga a actualizar el perfil tecnológico cada año, donde ahora se revelan las funciones de ciberseguridad.
  • La clase de datos 56, reporte histórico de seguridad de la información, se construye sobre registros que alguien tuvo que centralizar y conservar.
  • There is no legal obligation to have a SIEM in Costa Rica.
  • CONASSIF Agreement 5-24 requires entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE to have monitoring capabilities, and its article 42 mandates an annual technology profile update, which now discloses cybersecurity functions.
  • Data class 56, the information security historical report, is built on logs somebody had to centralise and retain.

InternacionalInternational

  • PCI-DSS, en su versión vigente v4.0.1, exige registrar los accesos a los componentes del entorno de datos de tarjeta, revisarlos y conservarlos por un periodo definido.
  • ISO 27001 exige registrar eventos, proteger los registros contra manipulación y evaluar el desempeño de la seguridad.
  • NIS2 y DORA parten de que la entidad tiene visibilidad centralizada: sin ella no se detecta ni se notifica en los plazos que exigen.
  • PCI-DSS, in its current v4.0.1 version, requires logging access to cardholder data environment components, reviewing those logs and retaining them for a defined period.
  • ISO 27001 requires recording events, protecting logs against tampering and evaluating security performance.
  • NIS2 and DORA assume the entity has centralised visibility: without it there is no detection and no notification within their deadlines.

Requisitos mínimosMinimum requirements

  • Una plataforma ya licenciada, o la decisión de que el proveedor aporte la suya: son dos modelos de costo distintos.
  • Accesos administrativos a la consola y permisos de lectura sobre las fuentes que se van a conectar.
  • Una definición escrita de retención por tipo de dato, que es una decisión de negocio y no técnica.
  • Un dueño del lado del cliente que autorice cambios: sin eso, cada ajuste queda esperando semanas.
  • A platform already licensed, or the decision that the provider brings its own: two very different cost models.
  • Administrative access to the console and read permissions over the sources to be connected.
  • A written retention definition by data type, which is a business decision rather than a technical one.
  • An owner on the client side who authorises changes: without that, every adjustment waits weeks.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

Es un servicio continuo, contratado normalmente por doce o veinticuatro meses. La toma del entorno lleva de cuatro a ocho semanas: inventariar lo que hay conectado, encontrar las fuentes muertas, documentar lo que nadie documentó y estabilizar el volumen. Si el SIEM viene de años sin mantenimiento, el extremo alto del rango es el realista.

This is a continuous service, usually contracted for twelve or twenty-four months. Taking over the environment takes four to eight weeks: inventorying what is connected, finding dead sources, documenting what nobody documented and stabilising volume. If the SIEM comes from years without maintenance, the high end of the range is the realistic one.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

SIEMSIEM
Plataforma que centraliza los registros de todos los sistemas y correlaciona eventos para generar alertas. Platform centralising logs from all systems and correlating events to raise alerts.
IngestaIngestion
El volumen de datos que entra a la plataforma cada día. Casi siempre es lo que define el precio de la licencia. The volume of data entering the platform each day. It almost always drives the licence price.
ParserParser
La pieza que traduce el formato crudo de cada sistema a campos ordenados. Si se rompe, los datos entran pero no se pueden buscar. The piece translating each system raw format into ordered fields. If it breaks, data still arrives but cannot be searched.
RetenciónRetention
Cuánto tiempo se guardan los registros y con qué rapidez se pueden consultar. Define hasta dónde se puede investigar hacia atrás. How long logs are kept and how quickly they can be queried. It sets how far back an investigation can reach.
Fuente de registroLog source
Cada sistema que envía datos al SIEM: un firewall, un servidor, una aplicación, la nube. Each system sending data to the SIEM: a firewall, a server, an application, the cloud.