Which SIM product do you use?
Currently at work we have tons of logs and many tedious processes to check the logs from firewalls, IDS, proxy, events logs, patchlink, and so on. In a prior job, I implemented CISCO MARs, which worked ok from a network perspective, but fell short from a log management perspective. The products I'm looking at are Trigeo, Network Intelligence, and Arcsight. I'm steering more for Trigeo because of the open platform, and it has tons of flexibility and control. The price is also much better than the rest. Also, the open source SIM OSSM has. With all that said, which products does everyone use and/or recommend.
Thank you everyones input and time.