Video: The Next Evolution of LogRhythm SIEM for the Modern SOC | Duration: 3196s | Summary: The Next Evolution of LogRhythm SIEM for the Modern SOC | Chapters: Welcome and Introduction (8.88s), Quarterly Launch Overview (35.39s), Exabeam Portfolio Overview (115.45s), Promises Kept Roadmap (186.82s), AIE Detection Integration (273.485s), AIE API Introduction (462.495s), Salesforce Collector Updates (703.865s), AI Events Dashboard (976.86s), JSON Policy Builder (1633.84s), Dashboard Integration Features (2501.61s), Expanding Metadata Fields (2612.66s), Behavioral Analytics Benefits (2703.21s), Deprecating Events Database (2772.485s), Future Reporting Plans (2855.575s), Future API Plans (3032.86s), Conclusion and Thanks (3120.355s)
Transcript for "The Next Evolution of LogRhythm SIEM for the Modern SOC": Hello, everyone, and welcome to our webcast. My name is Brook Chelmo, and I'm here with the irrepressible Ryan Gamboa. He's our senior product manager here over the LogRhythm platform. Sorry. Ryan has been here for quite some time and loves this platform and has been developing this with our customers day in and day out for quite some time. So, Ryan, if you'd like to quickly say hi, that would be great. Yeah. Thank you. Good morning, everyone. Thanks for giving your alert queues a short break and and joining us today. Yes. So, again, happy New Year. Welcome to 2026. Today and this this is our first launch of this year, and there will be three more following this, because we launch every quarter at the beginning of every quarter. So you'll see three more from us this year as you saw for last year. So with that said is we're gonna do a little bit of an overview of the portfolio. We're gonna talk about our promises made and promises kept, and you can see some of that development quarter by quarter over the last number of years. And then, of course, we're we're gonna actually get into what is new in this release followed by a demo given here by Ryan. We'll do some q and a. So please feel free to go and throw over any questions that you may have into that q and a. We will feel those as we go. We have three people on the back end of this webcast, also tending to those questions that you were sending over. Maybe can do a few little, bits of, troubleshooting if you do have an issue. We do have some polls. So, again, please mute your phones. Please not multitask if you can and focus on this one here. We really appreciate you again. So with that said, we have that demo there, okay, or that the agenda there. So this is the over the overview of the Exabeam portfolio here. So Exabeam new scale platform over there, as you can see, is going to represent that cloud based offering where for LogRhythm is going to be doing the on prem and hybrid deployments with NetMon as a shared resource between the two of those. You'll hear terms like LogRhythm SIEM or LR SIEM is kind of the nickname for that. That's the base SIEM package. And LogRhythm Intelligence is gonna be adding that UEBA engine in there to really purify and eliminate false positives and all the benefits that behavioral analytics will bring to the environment to help you determine what is something that you should be paying attention to more than other things. Similar, the kissing cousin on the the Exabeam side or the NewScale analytics sorry, NewScale side is NewScale analytics. Same difference there. That is their UEBA engine there. So Exabeam, our NewScale Fusion is the complete platform name. So that's some kind of nomenclature and terminology that you'll see, from here. Here is our promises made and promises kept slide. This is updated every single quarter. As you can see here, going back to, you know, a couple of Januaries, you can see what we've done here. And we're gonna get into the details, but we share this every single quarter to show you that this is what we've committed to. This is what we've done. And you can see us quarter by quarter by quarter consistently delivering on this road map. I have never been in a company, and all these years in tech and everything else from all spans and walks of life within cybersecurity, IT security, etcetera, I've never seen a company execute like this before. And this is what they do, and you're gonna see us believe it or not, April 1. I tell people, let's not have a launch in April 1, but this company is dead set on having those quarterly launches at the beginning of every quarter. So with that said, as you can see here, the the you know, over, you know, 1061 or so, you know, product improvements and support sorry. Product supported. A lot of other types of logs supported. A lot of other developments that you've seen over 2025. Key improvements and a lot of other changes over the course of this year. Not to really get into all of these details here because I don't wanna take away from what Ryan is saying. But, again, Ryan, from here, I think it's appropriate for you to take us forward, and I will sit back here and watch the q and a. Thanks so much, Brook. I said good morning earlier, but I know everyone's coming from all over the world, and I know you guys are busy out in the trenches. Our goal, you know, with with this release and and every release is to make your jobs easier. And I think those last couple slides really speak to that that and show that we're really committed to it. We're committed to the LogRhythm and product line. It's it's not something that we're we're just letting sit stagnant. And if you haven't had the opportunity to upgrade recently, you're sitting on an old version, Hopefully, this the those those slides and what we go through today push you to to want to get that upgrade in and get some of all all the goodness that we've we've delivered over the last year and in this quarter. So, with that, I want to just kinda jump into the key updates in 07/23. As usual, if you've attended these before, you know, we kinda go through some slides. We talk about the problem that we're trying to solve, what the solution was to to solve that problem, and then most importantly, you know, the benefit to to you. So our our overarching theme for 07/23 is is about efficient efficiency and unification. We're closing gaps that that that bring our analyst experience kinda closer together, a little more seamless, and giving administrators some powerful tools for for automation. After we go through the slides, I'll jump into a live demo as per usual and, show those features in action. So, I think I've kept the slide where it's short. I think I only have a 100 of them, so so don't worry. Okay. So first up, this is a a really big one. This is AIE detections right on your data index or dashboards. As an analyst, we we know that seeing everything in one place is critical. We know that it's really frustrating to have to jump from dashboard to dashboard, pivot between different views. We need to see everything all in one place along with the raw logs, and in context. The the context switching really breaks up your your concentration. It wastes precious time, especially during, you know, an investigation. So we've made AIE events available now and a data source that goes into your data indexer so that they show up on your data indexer dashboards, which means you can now build widgets that place those high fidelity AIE detections right next to all the other other underlying data and within, you know, your your top x widgets, it creates this single unified view for your threat hunting and investigations. So super, super important there. This is a really visual feature. I'll show you exactly how to set it up, make sure that those logs are going to the DX, and then I'll show you, you know, how to how to use those widgets during our demo in in just a few minutes. Alright. Very similarly, in in sort of the same vein, updating our our DX dashboards, we're bringing the threat map visualization to those DX dashboards as well. A big part of understanding a threat is knowing where it's coming from. So you need to visualize data in different ways, including a geographic map that is is really powerful in those investigations. Like AIE events, the threat map was stuck in our legacy event dashboards and didn't exist on the DX dashboards. So we've we've brought that now to our our DX dashboards. And while we were at it, we gave it a nice refresh. So we've now got a new higher quality, map provider, and I'll show that off again, in our demo. But this will, you know, give you that instant ability to correlate global activity with with all your other data, help spot trends, pinpoint threats, and and just just like the last feature, you gotta you gotta see it. So we'll we'll show that off in the demo. Okay. Switching switching gears a little bit. We're we're jumping over to more of the administration side. This one is really for, those administrators. We know large enterprises, NSSPs. We know managing those manually can be really, really challenging, especially across dozens of deployments. It it it can be a nightmare. It just doesn't scale. So, that's why we've we've finally introduced the AIE API. Finally. I know this has been, requested for quite a bit. This will allow you to programmatically import, enable, disable, and restart AIE services. This is really a really important foundational step for detections as code. You can now script the rollout of of critical new, rules across your environments, and it makes it so much speedier, consistent. It reduces the, massive amounts of manual effort. And I can all I can hear you guys all typing already in the questions. Ryan, what the heck? Why only import enable, disable, and restart? And you you guys are absolutely right. This is a a small subset of what, you know, AIE admin tasks you you actually need in order to get to the dream of detections as code. But but don't worry. As as I mentioned, this is a foundational step. There is much, much more to come. This is just where we were able to get this quarter, what we were able to get done in this version. And we know there's there's still user value in exposing just these endpoints. Right? Even if we didn't get all all of it available, we we wanted to give you, at least this value. So come back next quarter for for even more on a I AIE admin API endpoints. That is a mouthful. AIE admin APIs. Alright. So let's see. Let's keep going. Get through the slides and and to the fun stuff. Okay. While we're on the topic of making administrators' lives easier, let's talk about, this new Salesforce, collector that we've, we've launched this quarter. So our old way of collecting Salesforce data, it was clunky. It went through the system monitor agent, and it it, the biggest pain point was, that that collection logic was tied to the agent itself. Meaning, you you had to wait for updates to the system monitor. You had to actually update the system monitor, and and then only then you would get those those updates. So our solution is is to move that Salesforce collector away from the system monitor, make it part of our modern open collector framework, and that decouples the collection logic from the agent. It means faster, easier updates for you. It means a more flexible and efficient way of of collecting this data, and getting it into your SIEM. And, really, this follows our path of moving, all of that legacy those legacy collectors from the system monitors over to OpenCollector. And to everyone's, favorite, most relaxing activity, parsing JSON. I'll pause for comedic effect. Thank you. But but, yeah, I I didn't I didn't think anyone really loved doing this. We know it's painful. It's frustrating. It takes time. And the old the old builder, did not make it any easier. We knew it had, some some rigidity to it that, didn't allow you to to parse the logs, how you wanted to. So, we, we went and updated, redesigned that web builder tool to make it much more easier to handle things, like complex nested JSON, as well as arrays, and also modify existing policies. Right? If I created a policy before, and put it into use and maybe a a month later realized, hey. I wanna I wanna edit that and change, how I'm mapping something. You couldn't just reimport that and make the change quickly. You had to start all over again. So that was really, really painful. So it's a huge, quality of life improvement, because, yeah, it it it saves a lot of time there. So, that one will will show off in the demo as well. And finally, our last slide, I think I joked about having a a 100 slides earlier. I decided to be merciful. So you guys are getting off pretty easy, but we'll wrap up here with some platform updates and and jump into demos. We're always working to ensure LogRhythm runs on the latest, you know, most secure infrastructure. With seven twenty three, we're adding full support for Windows Server, 2025. We also are are supporting Rocky 10. And then we made some updates to the system monitor so that the Linux system monitor agent include some of the, functionality that wasn't available. It was only available on the Windows version of the SMA. So, the JSON listener, you had to point your JSON to a Windows version of the system monitor agent. That is no longer the case. You can now use a, a Linux one to to do that same workflow. So it just depends on what you you prefer, but, making sure that our agents on on both operating systems have that, have equal functionality there. Alright. That that covers the the highlights in, 07/23. So we're gonna pivot from slides over to our demo. Give me one sec to switch gears. Just a sec. Find all the right buttons. Alright. I'm gonna count on you, Brook, to tell me if we're if we're not seeing my my VM it. here. It. looks great. Good. Awesome. So let's start with our our AIE events. The first thing I wanna do is just just kinda describe what's going on here and how to set it up. Traditionally, AIE events, they're they're events. So they were written to the events database and not to the data indexer. As we, move to reduce our reliance on SQL, move to more modern database architectures on the back end, like Elasticsearch, we we wanna make sure that those logs, those events from the AI engine are also written to the the data indexer that, again, reduces our reliance on SQL, but it also brings those logs to to the data index or dashboards. So a a when you set this up, your detection's made by AIE. When it creates a new event, it will continue to write that log to the events database, but it will also create a copy in the data indexer. This ensures that reporting any of your old legacy events dashboards, all of that still works. Right? We didn't wanna interrupt that. We will continue to to move things out of the events database, including reporting, where our our vision is to to move that out of there, but, we didn't wanna interrupt that for now. So to create, the duplicate log that gets written in the data indexer, it's a really simple setup. You go to your AI engine, and you tell us where you want to send those logs. So this these two fields here are new. We've got a primary DX cluster that you can send send a copy to. You can send a second copy to a different cluster. So if you want a backup, say, in, like, an AJ scenario, that's that's available. So very easy. It's a drop down. This will populate with all your clusters. I only have one in this one. I can also use none. By default, it's it's actually set up to none. So this will just continue sending logs to the events database. And then if I select a cluster, it will send to events as well as this DX cluster. If I set up a a secondary one, it will send to all three locations. Alright. So that's the setup. That's it. Restart services, and that'll make sure those logs are getting sent over. And now now you're off to the races. We can we can start dashboarding. All those new detections made by AIE will get inserted into the DX. You're not gonna have any, you know, retroactive logs coming from the events database, but but anything new will will show up there. Alright. So I'm I'm on a dashboard here. Just as a quick recap, if, if you want to create a data index or dashboard, it's really simple to go to new dashboard, and select the data index or dashboard version. I've got one set up here already. I've I've got a couple widgets. These are just top x widgets that I've sort of configured already. I'm saving, you know, the the juicy bits for to show you here, but I've I've gone through I've I've already given it a title. I am grouping by common event field on this one, and I'm I'm using the mode count. Right? So this is this is counting every single common event that has gone into the DX dashboard over the last fourteen days. And it's not a very busy environment, so I've I've only got about 800,000 logs. But I want to filter now just on AIE detections. So that's that's pretty easy for me to do. AIE logs all have the same sort of common event structure. Right? They all begin with AIE colon. So I can come in here and say, you know what, where common event is AIE star and apply that, and that's gonna look at just those AIE logs. Smilarly, this so so this is a total count over the last forty days or sorry. Fourteen days. Maybe I wanna break that out a little more, and I wanna show each individual AIE detection. So I have another one set up here. Very, very similar, last fourteen days, but I'm I'm using a a top x widget instead of the single metric widget. And I'm gonna do the same thing. I'm gonna say common event is AIE star and apply that. And now I've got just my AIE detection showing here. So I can have these widgets that just show me those detections. Maybe you wanna keep this just to the last, like, three hours just to see what's coming in and relevant right then, or you can expand it to something more like thirty days for reporting purposes. So really powerful. And, again, I can I can even drill into this? I can go to view logs. This is gonna go query for those AI logs straight from the DX. Couple call outs I I want to mention. In, previous versions, we had issues with the text being case sensitive here. So if you did AIE verse, capital AIE, that was different. That's fixed in 07/23. It does not matter, if you use capital letters or lowercase. We are case insensitive in these filters here. So, that's, super helpful. But I also wanna call out some some oddities in, how we're storing AI engine events in the DX. So when when AIE sends a log to the DX, it it doesn't send, classification equals suspicious. It's sending classification ID equals 1234. So the the DX is actually storing an ID instead of this actual value of suspicious. We, we aim to change that and actually store the suspicious piece, because by storing the ID, we don't get, some functionality here on the DXs. So this is this is planned for our next release, but I wanna call this out because you'll you'll probably run into it. And you'll notice it here in the drop down. You'll notice that suspicious and attack, they don't quite show up like, some of these other ones do. Right? I have AI engine events here show up in my drop down. I don't get it in classification. I get it in common event. I might not get it in some other other fields. So that, we are we are working to enhance. We plan to send the actual values over the DX, store them instead of the IDs, and that will solve this. The the other area where you'll see this and may cause confusion, thus, the tips and tricks portion of our webinar here is in the widgets themselves. The widgets do this as well. So if I configure this one and pick a field, where we're storing IDs instead of the the actual values, so back to, like, classification, you'll notice that this this shows that it doesn't have any avail available data. Again, it's it's trying to create a widget on a value that's just not there. The ID is there. The actual classification name is not. So it it wasn't able to to show that. So, again, not holding back some of the the goodness of creating and getting, these these events over to the DX. But in our next version, we'll have one more, enhancement to make sure we we allow you to really dashboard and, group by all of these fields. Alright. So that is the AIE events on our dashboards. I'm gonna switch over to the threat map. You can see I already have it here. It is, you know, I already have maximum amount of, widgets here on my dashboard, but, it shows up in our our little add button now. Click and drag just like any other one. And, also, just like any anyone, we can, add some filters here. So I can I can say, hey? I'm just interested in, a certain, IP address or whatever field I I want to filter on. I can change the time range per usual. I can also, toggle a few different things, like displaying origin or impacted as well as the the legend itself. Not much has has changed in terms of configuration. Where you're gonna see the change is, obviously, that it's it's now available on these DX dashboards. But as you zoom in, you'll get a little more detail on on the map itself. So, just a a a little more enhancement there for for the exact details, within, borders and and cities, things like that. But, yeah, it brings brings all that data right here to your your DX dashboards. Okay. So, that covers the analyst portion. I want to jump over to our JSON engine. And to do that, if you have not found this yet, very easy to find our our policy builder up here in our resource center. We have a an easy link to it. And you'll notice that it looks quite different. It now is a little more of a wizard style, and it has a a whole lot more functionality. So I can create a a new policy here. I'm just gonna call it example. I can then tell it, just like before. I can either add, manually some logs. I can upload from file. And if I have a whole bunch of, you know, multiple logs, instead of this manual input of a single log, I can do I can do multiple as well. So I'm just gonna grab one that I've got here. Let's grab this one, and I'll paste it in. Actually, you know what? I I wanna do the other one because it's got a very specific thing I'd like to point out. Alright. So I pasted this in here, and you'll notice in my notepad, a couple things that we did not handle very well before when trying to parse out these logs. The first thing is arrays. So this this is an array. You can tell by the square bracket. And the other thing that we didn't handle well is right here in this data key pair. This is actually a nested JSON. Right? This is the log that I really care about inside of this data, key pair. And we, again, didn't didn't allow you to, kinda map these fields. They would, just it just wouldn't fan out. So as I paste this in here, you can even beautify it if you want to better read it. But as I paste it in, you can see that it it detected some nesting levels. It found an array. And then as I as I click next, it will show me that information. It'll say, hey. For for one of those nested that that nested JSON in there, we found it under the data key pair. Do you want us to fan that out? Right? I can I can select it? That means it's gonna fan out. And then I can also tell it where my array elements are as well. So, I didn't really have anything in here, so I'm not gonna select the array. But as I click next, this is where I add my filters. So, typically, you know, you're gonna filter on, like, beat name. You'll say, hey. Where my beat name is, whatever you've named your beat, or, it could be one out of the box, you want to apply this policy to. Right? So I've set that up. You can, add multiple conditions, obviously, and then we start getting into mapping. Just like before, we we would take a field and map it to the LogRhythm fields. It looks a little different, but, it's pretty straightforward. So I'm gonna take, I don't know, host name. And when I select it, it's gonna act ask me, you know, okay. Well, what what LogRhythm field do you want to map that to? Right? Maybe what did I select? Host name. So I'd I'd find my host in here, and select that. I'm just gonna select something. Doesn't really matter for demo purposes. You can tell us the, data type. Right? Is it a string? What is the format? If it's a date time, you can, you can add that as well. It it is optional. Some other optional, things that you can mess with are default values. Right? If if if this is blank, and and doesn't have anything, you can populate it with something. You can even say, hey. If this field doesn't exist, then let's use let's use an alternative field. So you can kinda create this if, then or scenario to to really customize this out. So once once you've gone through actually, I I should've, gone ahead and kept that for my demo, saved my mapping. It will show these mappings on the right, and I can do multiple. Right? So select something else. Now I've got all my things mapped out. I can now take this and do, some even even do some sub sub transforms. Again, this wasn't something that was available inside of, the last rule builder. I don't have any, for for this one, so I can skip. But what I want to call out is the, the export here. So once once I've got it, I can just download it. I can copy it to my clipboard and put it into my own text file if if you've already got something, know, and maybe you're just modifying an existing one. I'm gonna go ahead and download this for, my custom policies folder here in my JSON. It's probably in oh, there's downloads. Here's my example JSON. We'll cut that, and we'll put it in here. Right? And now that is, in my policies, it will be applied to that beat. But the the big thing, you know, if I reset this wizard, right, I've I've done this. It's been many, many days since I've I've done this, and I probably closed this tab. I've lost my work. That was a big problem. I I'd have to come in and recreate everything that I just did. This now allows me to update an existing policy. I can select this instead of create new, and I can go back to my example JSON here and just drag it in. And now I've I've got my policy in there, and I can step through all the steps again and edit it. So very simple to to modify that. You can even modify, an existing one. Right? This was another big use case was, hey. LogRhythm, you've you've missed a field that is critical to to, our workflows and our parsing needs. I'd like to modify this Event Hub, JSON policy to, include that field. So you can modify it and then and then dump it into the custom policies folder, so that it takes precedence over the the out of the box one. So much, much better. Hopefully, you you all have have seen this already and got to play around with it. If not, go out. Happy parsing, but I I hope that that makes your lives a a lot better. Okay. So that covers most of our demo. Let me just check our questions here, make sure I'm. not missing have. a few of your Alright. K. Alright. Will AIE events in the DX be visible via, the Windows console? Yes. They are. It's when you query the events database, obviously, you're querying just the AIE logs, or or events. If you switch make sure you move that toggle over to querying, the data indexer. But, yes, they will be available there as well. Question about drill downs on the DX dashboards. We do have some plans to to make that drill down, a lot better. We plan to get rid of the caching mechanism for AIE events, and just store the IDs of the logs that that triggered any logs. So, we can go directly and and query the logs that triggered any any alarm or or detection. That is actually in the works. We'll have a little bit of of that showing next quarter. It won't be fully, replaced, but, you'll definitely see some of that. And that will that will bring some more better workflows for those drill downs into the DX dashboards as well. When you say copies of data on two class with two clusters or DXs, does that mean all index data will be the same on both sides? It it will. Yeah. So if you're if you select two clusters, we are literally sending a a copy. So you'll have the exact same information sent from AIE to both clusters, and you'll have, replicated data in each. I guess a good call out here is when you're setting up your DX dashboards, you may want to just be very specific about which cluster you're, you're querying so that you don't get duplicate information on there. Let me see here. We've got are there vendor created DX dashboards in the community? We we do not have a whole lot out there currently. Our focus is trying to get some of these dashboards a little more meat to them, right, adding new widgets, new functionality, and we'll we'll follow-up with content after that. Alright. Hey, Ryan. Let's see. I I'm used to different platforms where the the polls come out automatically, but I can ask a poll question now just. to more just gonna gauge some interest. And I like the first one that we have hit written here, and I'm gonna open this now. But how would you describe the impact of alert fatigue and manual event correlation on your security team's effectiveness? So I'm gonna open this now. Three answers. It's a minor issue we manage well. It causes some inefficiency, a significant drain, or it's a critical problem that directly impacts our risk posture. So I don't wanna leave the witness here, but it this is a major cause for concern when it comes to turnover in the SOC. So, hopefully, I've I bought you a little time, Ryan, to dig up a few. questions you wanna answer. But There's a question about LogRhythm intelligence and and whether or not it's for air gap networks or if it requires Internet access. It does require Internet. We're sending logs from the SIEM up to a cloud environment, very similar to how we were doing things with, UEBA in the past. But, you you know, we gotta send it to the cloud for, that UEBA detection, and then alerts are sent back down to the SIEM. So, yeah, we we do require Internet access there. Good. Alright. Is there any maintenance that runs to help keep events from taking up space on the DX, or do we need to manually, keep a TTL? Good good question. So, as I mentioned, sending logs to the DX from AIE, is not a, is not out of the box. Right? You have to go set it up. And while it's probably a very minimal amount of logs, right, it's it's not a very chatty log source for most customers. It it can be chatty for for others. So it just depends on what you've you've set up. And that's one of the reasons we didn't, turn it on by default. The TTL for those events is in line with the rest of your data indexer. So if you're keeping logs for a year on your data indexer, those AIE events will also be kept for a year in the data indexer. There's no additional maintenance that that you need to turn on or or set up to to change that, or or to make sure they're getting cleaned up. They'll just get cleaned up with the rest of your logs. Ryan, can I push another poll? And then I have. a question for you to do this. So. I'll push this next poll over here, and then I'll ask a question that I see here. But, when you think about your security visibility, what is the biggest obstacle your current SIEM faces in today's, you know, landscape? Open that up. K. Is that visible to everyone? So difficulty yeah. There we go. So oops. There we go. So you guys can read that yourselves. So a question for you, Ryan, while they are looking at that polling So the new unified dashboard in AI e events and the threat map look great. Do I have to rebuild all my old dashboards from scratch to use these new widgets, or can I add them to my existing DX dashboards? Existing DX dashboards do not need, to be rebuilt. You can you know, as you go on there and look for more widgets, more widgets will be available. You can simply drag and drop new widgets onto your existing DX dashboards. If you're trying to take a dashboard from the events the legacy events dashboards and move them over to the DX, there are a few things on there that that may not work exactly the same. Usually, it's the the Lucene filters. Some of the syntax is just slightly different. So if you if you do take some of those Lucene filters and just copy them over to a a data index or dashboard widget, you may just have to modify the Lucene query slightly. Okay. Yeah. I've got another one here on, asking questions around, you know, what our plan is for, kind of expanding metadata fields in our schema. Really, really good question. I know we have a limited amount of, fields today, which means that we can't always parse all the fields in in a log, or you're or you're reusing a field for, something that doesn't necessarily make sense. Maybe it sort of works, but sort of doesn't. Yeah. We we do plan to expand the schema. Our our plan, though, first is to move more away from SQL. Today, if we expand our without getting really into all the weeds, but to expand our schema is quite a bit of work because we're expanding it in two places. We've got Elastic as well as SQL. Right? Our reporting engine, we're we're it's just the the load there is is pretty pretty big, and it doesn't make sense for us to to sort of do that when we already plan to to deprecate some some of the pieces of, the SIEM. So we we do plan to make a a few stepping stones first, but that that is in our our future for sure. So with that said, Ryan, if I can interject here, on the screen, we have the LogRhythm Intelligence kind of, feature brief that you can read here. This is adding behavioral analytics to your LogRhythm deployment. Strongly, you know, encouraged. The one reason why, again, adding UEBA or behavioral analytics will help you find insider threats easier, quicker, faster, smarter, better, all the adjectives you can think of out there today just because you're being able to baseline abnormal from normal behavior. And finding identity based threats can sometimes be very difficult when you have a compromised credential or or something more or less or a compromised insider or even a malicious insider. So feel free to take a look at that brief that may be in the documents, but also you can take a picture of that QR code with your phone. I'll open the last poll, and then we can maybe ask another question. So during a typical security investigation, what is the biggest bottleneck slowing your team down? So feel free to answer that one. Ryan, do you have a question that you wanna pick, or shall I pick one? Yeah. I think I've I've got one more here. Okay. I think we've gotten all of them except except this one. If we did not get yours, I I apologize. We will we'll go through them here at the end, make sure we, get back to anyone after the call if if we've missed them. Yeah. Give everyone a few more seconds to finish that poll. I know multi I I'm not good at multi multitasking, so I'll let everyone read. Everyone who claims they're good at multitasking usually isn't anyways. So there is some sacrifice, which is why I always ask folks, please pay attention. You know, they as much as we think we can answer email and pay attention, we just don't. Alright. So I'll I'll jump into the the last question here. I think this comes off of my my comments around, you know, getting rid of the events dashboard or events database and, you know, the SQL comments. But but the question is, you know, what are what's our timeline and our plans for fully deprecating the events database, moving over the the data indexer? Will there be a specific version where we get rid of the events database completely? I I think, yes. Eventually, we will have a version where it is gone. What version it it is, I I can't say. I I think we we still do have a a long road ahead of us to to get there. The the main piece is is reporting. So our our plans within the more immediate future is to introduce a a scheduling a new scheduled report option, based on the the DX dashboards, to kinda take the load off of, you know, our our old reporting engine, that that we know is is clunky, really not not a very useful reporting engine in in a lot of ways. But a lot of our content is built off of the events dashboard. So the all the KB reports, etcetera, need to be moved over to the whatever new reporting engine that we we build and pointed to the DXs instead of the events database. So I see us living in a world where, we've got sort of both the events database still existing along with the DX until we can we can move a lot of that content, over to to the. new architecture. Hopefully, that that answers the question without, you know, a real time line there. And I know I I can't provide futures that far out. Kinda kinda hard to say, but, hopefully, that that vision, makes sense. And and it's clear that, you know, we're heavily focused on on delivering features and things that that really impact, you know, your your day to day work. We we know where we need to go. It will be incremental. And this is all part of our our ongoing commitment to investing and involving LogRhythm SIEM. I know some people are still, confused about where we are with the LogRhythm and whether or not it's it's staying around as a product. And I I hope that this really shows that, the LogRhythm is is here to stay. We're we're planning to invest in it, modernize it, and add feature set that that you guys need. We're actively investing. Now that we will invest in it. We are actively investing in it. You know, we have our own dedicated engineering team here, and there is a road map that, you know, we're executing upon. In fact, you're gonna see this next webcast most likely without putting, you know, words in the mouth of our campaigns team, April 7. So we'll be there. Ryan, can I ask one more question? We could wrap this up today. Yeah. Let's do. it. Alright. So the new AI, you know, admin API is a great start for automation. Right? So what are your plans to expand that capability that you see there? And, for example, will we be able to edit rules via the API down that line? Yeah. Good question. So targeted for next quarter, we are planning to go after if you if you open up an AIE rule, and go to the settings tab, there's a there's a lot of stuff on there, you know, from the the classification settings to whether you want to alert on an AIE rule, segregation, lot lot of other items on there. So we're we're targeting that tab for next quarter to to get as much of that, those functions done and and a part of the, the endpoints, as as well as the information tab. That's our next step. Step after that will likely be getting to, actually modifying some of the rules. Or sorry. I shouldn't say the, just the rules, but the the rule blocks themselves, I think, is is really what people are after. So, yeah, like I said, multistep, but, next week, we'll have, next quarter, we'll have some more. And then the quarter after that, we'll just keep marching down and checking stuff off the list. Alright. So put your calendars down now. I'm gonna say April 7. You'll see it's again here. But there will be a launch on April 1. It is not an April fools April fools joke. It's a real product announcement, so you'll be hearing more from us. So, again, thank you very much for attending today's call. My name is Brook Chelmo here on the product marketing team. I'm, again, super glad to have Ryan Gamboa here from our product team who represents not only the product team, but also the engineering team that goes behind this. He interfaces with them on a daily basis to deliver these improvements to you. He is also in the field talking with our customers and speaking with them. So we are a customer first organization. We are designed solely on trying to solve customer problems to make things more efficient for you, which you can take a look at the polling questions that we've asked you. We really wanna know where the pain is to really help you solve those problems and keep developing on that. So, again, we thank you from around the world. We know we have attendees from every almost every country on Earth and every continent for sure. So, again, thank you very much, and have a great day.