3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Provide your catalog of prebuilt connectors for [log sources in scope], stating for each connector its collection method, its maintainer (you, the source vendor or a community contributor), whether it parses events into your common schema and its last-updated date.
Why it matters. Connectors maintained by third parties or the community may not be updated when a source changes. The buyer then has to repair collection gaps it did not plan to own.
Good answer
- Each source in [log sources in scope] is listed by name with its collection method (agent, API pull, syslog, cloud storage).
- The maintainer is stated for every connector.
- Each entry shows whether events are parsed into the common schema or collected only as raw text.
Red flags
- A total integration count with no source-by-source list.
- Connectors that only collect raw events are counted as supported without saying so.
- No maintainer is stated, or all connectors are described as vendor-supported without distinction.
2. For each point in the data path where your product can apply filter rules before events are stored for search, such as a collector we host or your cloud service, state the filter actions available at that point.
Why it matters. If filtering happens only after ingest, the buyer pays network and processing costs for data it then discards. It also cannot keep sensitive fields off the platform.
3. For each storage tier your product offers, state which of these functions work on data held in that tier, with any limits that apply: interactive search, scheduled detection rules, dashboards and retroactive threat intelligence matching.
Why it matters. If detection rules or searches stop at a tier boundary, events older than [hot retention period] are not covered by detections or hunts the buyer assumes cover them. The buyer cannot size [hot retention period] without knowing what stops working after it.
Capability areas
Data Source Onboarding & Normalization (12)
Prebuilt collectors and connectors for security-relevant sources (endpoint, identity, cloud control planes, network, SaaS), custom parser creation, field normalization to a common schema, and handling of parser breakage when source formats change. Out: generic enterprise APIs and SSO, covered by the integration module.
Ingestion Pipeline, Filtering & Source Health (10)
Pre-ingest filtering, sampling, enrichment with asset and identity context, and routing of events to different destinations; ingestion latency; detection of sources that stop sending or send malformed data. Out: pricing terms for ingestion volume, covered by the commercial module.
Storage Tiering & Retention (9)
Hot, warm, cold and archive tiers, search behavior across tiers, rehydration of archived data, federated query against external security data lakes, and log immutability and integrity for retained data. Out: vendor-side backup and disaster recovery, covered by the business-continuity module.
Detection Engineering & ATT&CK Coverage (14)
Authoring, testing, versioning and deploying correlation and detection rules, detection-as-code workflows, mapping of content to MITRE ATT&CK techniques, vendor-supplied content updates, and tuning and suppression of noisy rules. Out: ML-based behavioral models, covered in UBA.
Behavioral Analytics & Anomaly Detection (10)
User and entity behavior baselining, peer-group comparison, risk scoring and accumulation across entities, baseline learning periods, and analyst control over model sensitivity and exclusions. Out: generative AI assistants, covered in AIA.
Threat Intelligence Integration (8)
Ingestion of indicator feeds over STIX/TAXII and other formats, indicator lifecycle and expiry, automated enrichment of alerts, and retroactive matching of new indicators against historical data. Out: the vendor's own security posture.
Search, Investigation & Threat Hunting (12)
Query language, search performance at the buyer's data volumes, entity timelines and relationship graphs, pivoting between related events, saved hunts and hunting notebooks, and hunt-to-detection conversion. Out: AI-generated query assistance, covered in AIA.
AI-Assisted Triage & Investigation (9)
Natural-language querying, AI-generated alert and incident summaries, automated triage verdicts, evidence and source traceability for AI output, and analyst feedback on AI conclusions. Out: model governance, AI safety and autonomy controls in general, covered by the AI modules.
Alert Triage & Case Management (11)
Alert grouping into incidents, deduplication, triage queues and assignment, case workflow and evidence collection, analyst collaboration, and SOC operating metrics such as MTTD and MTTR computed from case data. Out: external ticketing system connectors, covered by the integration module.
Response Automation & Playbooks (12)
Built-in orchestration, playbook authoring and testing, prebuilt playbooks, bidirectional response actions against EDR, firewall, identity and email controls, approval gates, and rollback of automated actions. Out: generic agent permission frameworks, covered by the agentic autonomy module.
Data Access Segregation, Audit & Compliance Reporting (11)
Restricting which analysts can search which data by business unit, region or tenant (including MSSP-style multi-tenant operation), tamper-evident audit trails of analyst searches and actions inside the SIEM, and compliance reporting and log-review evidence for regulated scopes. Out: the vendor's own certifications, covered by the compliance-certifications module.
Legacy SIEM Migration & Detection Parity (8)
Translation of existing detection rules, dashboards and saved searches from a legacy SIEM, parallel-run comparison of alert output, import or federated access to historical log data, and tooling to confirm no detection gap during cutover. Out: general implementation methodology and staffing, covered by the implementation-onboarding module.
Questions about this package
How many SIEM & Security Analytics RFP questions are there?
126 solution questions in 12 capability areas: 29 for the RFI, 63 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.