World Congress 2026 Europe - Virtual Stage Jul 5, 2026 Session details

Better Together: Leveraging Your Observability Tools as a SIEM

Mathias Palmersheim

Running separate agents for observability and SIEM drains resources and causes team friction. Discover how a unified telemetry pipeline slashes cloud costs and streamlines threat detection.

Pause
Mute Enter Fullscreen
#1 about 2 min

Background and origins of the Shiftmon monitoring project

An introduction to observability backgrounds and the creation of an open-source monitoring tool for small setups.

#2 about 3 min

Defining observability beyond basic metrics, logs, and traces

How correlating data from multiple sources enables proactive troubleshooting and accurate system interrogation.

#3 about 2 min

Core functions of security information and event monitoring

How SIEM tools collect telemetry to alert teams about irregularities and vulnerabilities before attacks occur.

#4 about 2 min

Shared stress and negative outcomes of critical system incidents

Why security and infrastructure failures produce identical stress levels, financial losses, and reputational damage.

#5 about 3 min

Unseen consequences of maintaining multiple separated telemetry agents

How installing disjointed collection packages leads to conflicting permissions, high resource usage, and incorrect blame attribution.

#6 about 2 min

Security risks from duplicated effort and increased privileges

Why maintaining parallel storage systems wastes resources and increases the attack surface through privileged commands.

#7 about 3 min

Investigative friction caused by siloed organizational tooling

How context switching across separate interfaces creates blind spots and misaligned priorities between infrastructure and security.

#8 about 4 min

Why differing legacy workflows complicate monitoring tool migrations

How disparate historical development paths and deep-rooted team habits stall efforts to consolidate systems.

#9 about 4 min

Communicating the value of unified observability to leadership

How framing tool consolidation around reduced labor, cloud savings, and cyber insurance secures executive buy-in.

#10 about 3 min

Aligning cross-functional teams with unified management pipelines

How shared dashboard views and pre-configured collectors enable simultaneous incident tracking across security and operations.

#11 about 5 min

Overcoming integration hurdles in consolidated monitoring platforms

Why migrating proprietary security indicators and extracting data from managed cloud services presents significant technical challenges.

#12 about 5 min

Building a unified stack leveraging core open source tools

How combining Telegraf, Grafana, and VictoriaMetrics provides a pre-canned foundation for infrastructure and security logs.

#13 about 3 min

Monitoring automated host compliance via open system instrumentation

How tracking systemd service states surfaces configuration deployment failures before cascading into larger outages.

#14 about 2 min

Correlating granular host system queries with network bandwidth

How combining endpoint process queries with firewall throughput enables rapid diagnosis of anomalies like data exfiltration.

#15 about 2 min

Using machine anomaly detection to resolve cross-team disputes

How referencing shared availability and response time baselines diffuses blame during complex incidents or vulnerability scans.

#16 about 2 min

Debugging application telemetry with unified network flow logs

How comparing trace pipeline behavior against network traffic rules identifies whether misconfigurations stem from ports or collectors.

Matching moments

45 sec

Introduction to easy mode observability and ShiftMon

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:59 min

Consolidating cybersecurity tools into a unified platform approach

Kai Grunwitz Kai Grunwitz +2 · WWC 2025

12:33 min

Exploring advanced observability stacks and distributed infrastructure challenges

Pawel Piwosz · LIVE

5:34 min

Consolidating observability data within a unified telemetry platform

Liam Hurrell · LIVE

2:21 min

Breaking down silos between developers, security, and ops

Stefania Chaplin · WWC 2022

1:17 min

Centralizing observability and monitoring tools across isolated edge infrastructure

Christian Koep Christian Koep · WWC 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Principal Engineer at Cadence

Vivek Pandit
Open session

World Congress 2026 North America

Microservice Cognitive Index for Deploy Diagnosis and Change Impact

Sachin Gupta

Member of Technical Staff 2 at eBay

Sachin Gupta
Open session

World Congress 2026 North America

AI Decision Observability: Enabling Transparency and Trust in Intelligent Systems

Amjad Shaikh, Soumil Mandal

Amjad Shaikh
Soumil Mandal
Open session

World Congress 2026 North America

Reinventing Incident Response with AI Agents and MCP

Jayant Tyagi

Lead Member of Technical Staff @ Salesforce

Jayant Tyagi
Open session

World Congress 2026 North America

AI-Powered Incident Triage: How We Built GenAI Agents with MCPs to Automate On-Call Workflows

Prakshal Doshi

Site Reliability Engineer

Prakshal Doshi
Open session

World Congress 2026 North America

The Geometry of Incidents: What User-Impact Shapes Reveal About Platform Architecture

Bala Subrahmanyam Kambala

Staff Platform Engineer at Oracle Cloud Infrastructure

Bala Subrahmanyam Kambala